vendor:
Creative Cloud
by:
Cyril Vallicari
7,2
CVSS
HIGH
Privilege Escalation Unquoted Service Path
426
CWE
Product Name: Creative Cloud
Affected Version From: 3.6.0.248
Affected Version To: 3.7.0.271
Patch Exists: YES
Related CWE: N/A
CPE: a:adobe:creative_cloud
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x64 SP1
2016
AdobeUpdateService – Privilege Escalation Unquoted Service Path vulnerability
The application suffers from an unquoted search path issue impacting the service 'AdobeUpdateService' for Windows deployed as part of Adobe Creative Cloud. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with system privileges on the system.
Mitigation:
Fixed in version 3.7.0.271