vendor:
Adobe Creative Cloud Desktop Application
by:
John Page aka hyp3rlinx
8,8
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: Adobe Creative Cloud Desktop Application
Affected Version From: <= v4.0.0.185
Affected Version To: <= v4.0.0.185
Patch Exists: YES
Related CWE: CVE-2017-3006, APSB17-13
CPE: a:adobe:creative_cloud
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2017
Adobe Creative Cloud Privilege Escalation
Adobe CC uses weak insecure permissions settings on the "Adobe Photoshop dll & Startup Scripts" directories. This may allow authenticated users to execute arbitrary code in the security context of ANY other users with elevated privileges on the affected system. Issue is the 'C' flag (Change) for 'Authenticated Users' group.
Mitigation:
Adobe has released a patch to address this vulnerability.