CVE-2024-30295: When Animate parses FLA files, there is a UAF vulnerability caused by referencing uninitialized memory at Animate.exe+0x1149dcf
Animate versions 24.0.2, 23.0.5 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30295?
CVE-2024-30295 is classified as a high-severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-30295?
To remediate CVE-2024-30295, users should update Adobe Animate to version 24.0.3 or later.
What versions of Adobe Animate are affected by CVE-2024-30295?
CVE-2024-30295 affects Adobe Animate versions 24.0.2, 23.0.5, and earlier.
What is a NULL Pointer Dereference in the context of CVE-2024-30295?
In the context of CVE-2024-30295, a NULL Pointer Dereference occurs when the application attempts to access memory that has not been allocated, potentially leading to application crashes or arbitrary code execution.
Does exploitation of CVE-2024-30295 require user interaction?
Yes, exploitation of CVE-2024-30295 requires user interaction, specifically opening a malicious file.