First published: Thu Oct 13 2016(Updated: )
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Creative Cloud | <=3.7.0.272 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6935 is classified as a medium severity vulnerability.
To fix CVE-2016-6935, upgrade Adobe Creative Cloud Desktop Application to version 3.8.0.310 or later.
Local users of Adobe Creative Cloud versions prior to 3.8.0.310 on Windows are affected by CVE-2016-6935.
Attackers can exploit CVE-2016-6935 to gain elevated privileges by placing a Trojan horse executable in the %SYSTEMDRIVE% directory.
There are no published workarounds for CVE-2016-6935; updating to a fixed version is recommended.