PT-2021-6038 · Adobe · Creative Cloud Desktop
Published
2021-05-11
·
Updated
2021-09-14
·
CVE-2021-28581
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Creative Cloud Desktop versions 3.5 and earlier
Description
The issue is related to an uncontrolled search path vulnerability. This could result in elevation of privileges. Exploitation requires user interaction, where a victim must log on to the attacker's local machine. The vulnerability can be exploited using a specially crafted file, allowing an attacker to gain elevated privileges in the system.
Recommendations
For Adobe Creative Cloud Desktop versions 3.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Creative Cloud Desktop