CVE-2021-40763 is a memory corruption vulnerability in Adobe Character Animator versions 4.4 and earlier, affecting both macOS and Windows platforms. This flaw allows for arbitrary code execution in the context of the current user when parsing a specially crafted WAF file. The vulnerability has a high CVSS score of 7.8, indicating a significant impact with high confidentiality, integrity, and availability risks, though it requires user interaction for successful exploitation. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, but it has garnered some community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4CPE matchmatch criteria | cpe:2.3:a:adobe:character_animator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.