CVE-2025-61804

7.8

Adobe · Animate

Adobe Animate versions 23.0.13, 24.0.10 and earlier are vulnerable to a heap-based buffer overflow that could allow arbitrary code execution when a user opens a malicious file.

Executive summary

Adobe Animate contains a heap-based buffer overflow vulnerability that could allow an attacker to execute arbitrary code on a victim's machine via a malicious file.

Vulnerability

This is a heap-based buffer overflow (CWE-122) occurring within Adobe Animate. The vulnerability requires user interaction, specifically that a victim must open a malicious file, and it can be triggered by an unauthenticated attacker.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve arbitrary code execution in the context of the current user. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, sensitive data exfiltration, or the installation of persistent malware within an organization.

Remediation

Immediate Action: Users should update Adobe Animate to the latest version provided by the vendor in security bulletin APSB25-97.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution patterns or unexpected crashes associated with the Animate application.

Compensating Controls: Implement file integrity monitoring and ensure that endpoint protection software is configured to scan external files before they are opened by users.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the potential for arbitrary code execution, this vulnerability poses a significant risk to workstations running Adobe Animate. Administrators must prioritize applying the vendor-supplied updates to all affected systems to eliminate the underlying flaw and prevent potential exploitation.

More Adobe CVEs

Sources