PT-2024-4228 · Adobe · Adobe Creative Cloud Desktop Application

Published

2024-06-11

·

Updated

2024-08-07

·

CVE-2024-34116

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Creative Cloud Desktop Application versions 6.1.0.587 and earlier
Description The issue is related to an uncontrolled search path element in the Adobe Creative Cloud Desktop Application, which could allow an attacker to bypass existing security restrictions and execute arbitrary code in the context of the current user by using a specially crafted malicious file. This can lead to arbitrary file deletion. Exploitation of this issue requires user interaction.
Recommendations For versions 6.1.0.587 and earlier, update to a version later than 6.1.0.587 to resolve the issue. As a temporary workaround, consider restricting user interaction with potentially malicious files until a patch is available.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-04714
CVE-2024-34116

Affected Products

Adobe Creative Cloud Desktop Application