PT-2020-6450 · Adobe · Genuine Service
Published
2020-07-14
·
Updated
2021-06-28
·
CVE-2020-9667
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Adobe Genuine Service versions 6.6 and earlier
Description
The issue is related to an Uncontrolled Search Path element vulnerability in the Adobe Genuine Service. This vulnerability allows an authenticated attacker with admin privileges to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction. The vulnerability is also associated with an insecure procedure for searching paths to DLL libraries, which could allow an attacker to load a malicious executable file and elevate their privileges.
Recommendations
For Adobe Genuine Service versions 6.6 and earlier, consider restricting access to the service until a patch is available, as a temporary workaround to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Genuine Service