CVE-2022-30664: Adobe Animate SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Jun 16, 2022
·Updated
Adobe Animate version 22.0.5 (and earlier) is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Animate>=21.0<=21.0.10
Adobe Animate>=22.0<=22.0.5
macOS
Microsoft Windows
Event History
Jun 16, 2022
CVE Published
via MITRE·05:09 PM
Data Sourced
via MITRE·05:09 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-30664?
The severity of CVE-2022-30664 is critical with a CVSS score of 7.8.
2
How can I mitigate the CVE-2022-30664 vulnerability?
To mitigate CVE-2022-30664, it is recommended to update Adobe Animate to a version that includes a patch for the vulnerability.
3
Is Apple macOS affected by CVE-2022-30664?
No, Apple macOS is not affected by the CVE-2022-30664 vulnerability.
4
What is the type of vulnerability for CVE-2022-30664?
CVE-2022-30664 is an out-of-bounds write vulnerability that could lead to arbitrary code execution.