CVE-2021-28581: Adobe Creative Cloud Desktop uncontrolled search path element vulnerability could lead to local privilege escalation
Published Sep 8, 2021
·Updated
Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in elevation of privileges. Exploitation of this issue requires user interaction in that a victim must log on to the attacker's local machine.
Affected Software
2 affected components
Adobe Creative Cloud<=5.3
Microsoft Windows
Event History
Sep 8, 2021
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-28581?
CVE-2021-28581 has a medium severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2021-28581?
To fix CVE-2021-28581, users should update Adobe Creative Cloud to version 5.4 or later.
3
What causes CVE-2021-28581?
CVE-2021-28581 is caused by an uncontrolled search path vulnerability in Adobe Creative Cloud Desktop.
4
Is user interaction required to exploit CVE-2021-28581?
Yes, exploitation of CVE-2021-28581 requires user interaction, specifically the victim must log on to the attacker's machine.
5
Which versions of Adobe Creative Cloud are affected by CVE-2021-28581?
CVE-2021-28581 affects Adobe Creative Cloud Desktop versions 3.5 and earlier.