PT-2021-6633 · Adobe · Photoshop Elements
Published
2021-06-08
·
Updated
2022-10-18
·
CVE-2021-28597
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Photoshop Elements versions 5.2 and earlier
Description
The issue is related to the creation of temporary files with insecure permissions in Adobe Photoshop Elements. An unauthenticated attacker could exploit this to call functions against the installer, allowing them to perform high-privileged actions. Exploitation does not require user interaction.
Recommendations
For Adobe Photoshop Elements versions 5.2 and earlier, update to a version that addresses the insecure temporary file creation vulnerability to prevent potential privilege escalation.
As a temporary workaround, consider restricting access to the installer to minimize the risk of exploitation.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Photoshop Elements