CVE-2024-30297: When Adobe Animate parses FLA files, there is a heap out-of-bounds write vulnerability at Animate.exe+0x125D391
Animate versions 24.0.2, 23.0.5 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30297?
CVE-2024-30297 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-30297?
To fix CVE-2024-30297, users should update Adobe Animate to version 24.0.3 or later, or 23.0.6 or later.
Who is affected by CVE-2024-30297?
CVE-2024-30297 affects users of Adobe Animate versions 24.0.2, 23.0.5, and earlier.
What can happen if I don't fix CVE-2024-30297?
If CVE-2024-30297 is not fixed, it may allow attackers to execute arbitrary code on the affected system.
Do I need user interaction for CVE-2024-30297 to be exploited?
Yes, exploitation of CVE-2024-30297 requires user interaction, such as opening a malicious file.