CVE-2022-38411: Adobe Animate SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Sep 16, 2022
·Updated
Adobe Animate version 21.0.11 (and earlier) and 22.0.7 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Animate>=21.0<=21.0.11
Adobe Animate>=22.0<=22.0.7
macOS
Microsoft Windows
Event History
Sep 16, 2022
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-38411?
CVE-2022-38411 is a Heap-based Buffer Overflow vulnerability in Adobe Animate.
2
What is the severity of CVE-2022-38411?
The severity of CVE-2022-38411 is high, with a CVSS score of 7.8.
3
Which versions of Adobe Animate are affected by CVE-2022-38411?
Adobe Animate version 21.0.11 and earlier, as well as 22.0.7 and earlier, are affected by CVE-2022-38411.
4
What is the potential impact of CVE-2022-38411?
CVE-2022-38411 could result in arbitrary code execution in the context of the current user.
5
How can CVE-2022-38411 be exploited?
Exploitation of CVE-2022-38411 requires user interaction, as a victim must open a malicious file.