CVE-2024-49526: Animate | Use After Free (CWE-416)
Published Nov 12, 2024
·Updated
Animate versions 23.0.7, 24.0.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
All of the following
Any of the following
Adobe Animate<23.0.8
Adobe Animate>=24.0.0<24.0.5
Any of the following
macOS
Microsoft Windows
Event History
Nov 12, 2024
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-49526?
CVE-2024-49526 is considered a critical vulnerability due to its potential for arbitrary code execution.
2
How do I fix CVE-2024-49526?
To fix CVE-2024-49526, upgrade Adobe Animate to version 23.0.8 or 24.0.5 or later.
3
What versions of Adobe Animate are affected by CVE-2024-49526?
Adobe Animate versions 23.0.7, 24.0.4, and earlier are affected by CVE-2024-49526.
4
What type of vulnerability is CVE-2024-49526?
CVE-2024-49526 is classified as a Use After Free vulnerability.
5
Can CVE-2024-49526 be exploited without user interaction?
Exploitation of CVE-2024-49526 requires user interaction, such as opening a malicious file.