CVE-2025-54279

7.8

Adobe · Animate

Adobe Animate versions 23.0.13, 24.0.10 and earlier are vulnerable to a Use After Free flaw that can lead to arbitrary code execution if a user opens a malicious file.

Executive summary

Adobe Animate is affected by a critical Use After Free vulnerability that could allow an attacker to achieve arbitrary code execution on a victim system.

Vulnerability

This is a Use After Free vulnerability (CWE-416) triggered when the software incorrectly manages memory. Exploitation requires user interaction, specifically the opening of a specially crafted malicious file by the victim.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it allows attackers to run unauthorized commands with the privileges of the logged-in user. With a CVSS score of 7.8, this vulnerability is classified as High severity, indicating that successful exploitation could lead to full system compromise, loss of data integrity, or unauthorized access to sensitive local resources.

Remediation

Immediate Action: Update Adobe Animate to the latest version provided by the vendor in the security advisory at https://helpx.adobe.com/security/products/animate/apsb25-97.html.

Proactive Monitoring: Review endpoint security logs for anomalous behavior in the Animate process or unexpected crashes that may indicate exploitation attempts.

Compensating Controls: Ensure that users do not open files from untrusted or unknown sources, and maintain robust endpoint protection software to detect malicious file execution.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant risk to end-user workstations. Organizations should prioritize updating all instances of Adobe Animate to the patched versions immediately to eliminate the underlying memory management flaw.

More Adobe CVEs

Sources