PT-2020-6361 · Adobe · Adobe Creative Cloud Desktop Application
Zhiniang Peng
·
Published
2020-03-24
·
Updated
2020-03-27
·
CVE-2020-3808
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Creative Cloud Desktop Application versions 5.0 and earlier
Description
The issue is caused by a time-of-check to time-of-use (toctou) race condition. Successful exploitation could lead to arbitrary file deletion. This can be exploited by a remote attacker to delete any file.
Recommendations
For Adobe Creative Cloud Desktop Application versions 5.0 and earlier, update to a version later than 5.0 to resolve the issue.
At the moment, there is no information about other specific mitigation measures for this vulnerability.
Fix
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Adobe Creative Cloud Desktop Application