CVE-2021-28581
Adobe Creative Cloud Desktop uncontrolled search path element vulnerability could lead to local privilege escalation
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.3EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
08 Sep 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges. Exploitation of this issue requires user interaction in that a victim must log on to the attacker's local machine.
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Affected products
Adobe · Creative Cloud (desktop component)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →