First published: Wed Aug 29 2018(Updated: )
Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Creative Cloud | <4.5.5.342 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5003 has a medium severity level as it allows for privilege escalation through DLL hijacking.
To fix CVE-2018-5003, update Adobe Creative Cloud Desktop Application to version 4.5.5.342 or later.
CVE-2018-5003 affects the Adobe Creative Cloud Desktop Application prior to version 4.5.5.342 on Microsoft Windows systems.
DLL hijacking in CVE-2018-5003 refers to the vulnerability where an insecure library loading mechanism allows an attacker to execute arbitrary code.
CVE-2018-5003 requires local access to exploit, as it involves running the vulnerable Adobe software on a targeted machine.