Vulnerability Details CVE-2021-42268
Adobe Animate version 21.0.9 (and earlier) is affected by a Null pointer dereference vulnerability when parsing a specially crafted FLA file. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 68.6%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2021-42268
-
cpe:2.3:a:adobe:animate:15.2.1.95
-
cpe:2.3:a:adobe:animate:20.5
-
cpe:2.3:a:adobe:animate:21.0
-
cpe:2.3:a:adobe:animate:21.0.2
-
cpe:2.3:a:adobe:animate:21.0.3
-
cpe:2.3:a:adobe:animate:21.0.4
-
cpe:2.3:a:adobe:animate:21.0.9