CVE-2025-21135
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 191
Summary
CVE-2025-21135 is a newly discovered vulnerability affecting Animate versions 24.0.6 and earlier, as well as 23.0.9. This issue involves an Integer Underflow, which can result in Arbitrary Code Execution in the context of the current user. The flaw is triggered when the software fails to properly manage integer inputs, leading to unexpected behavior. Notably, exploitation of this vulnerability necessitates user interaction; a victim must open a maliciously crafted file to be at risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.