CVE-2021-42271: Adobe Animate BMP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Animate version 21.0.9 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious BMP file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42271?
CVE-2021-42271 is an out-of-bounds write vulnerability in Adobe Animate version 21.0.9 and earlier that could allow arbitrary code execution.
What is the severity of CVE-2021-42271?
CVE-2021-42271 has a severity rating of 7.8 (Critical).
Which versions of Adobe Animate are affected by CVE-2021-42271?
Adobe Animate version 21.0.9 and earlier are affected by CVE-2021-42271.
How can CVE-2021-42271 be exploited?
Exploitation of CVE-2021-42271 requires user interaction in the form of opening a malicious BMP file.
Is there a fix available for CVE-2021-42271?
Yes, Adobe has released a security update to address the vulnerability. Please refer to the reference link for more information.