First published: Wed Sep 01 2021(Updated: )
Adobe Captivate version 11.5.5 (and earlier) is affected by an Creation of Temporary File In Directory With Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. The attacker must plant a malicious file in a particular location of the victim's machine. Exploitation of this issue requires user interaction in that a victim must launch the Captivate Installer.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Captivate | <=11.5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36002 has a medium severity rating due to its potential for privilege escalation.
To fix CVE-2021-36002, update Adobe Captivate to version 11.5.6 or later.
CVE-2021-36002 could allow an attacker to escalate privileges by planting a malicious file due to insecure temporary file permissions.
Users of Adobe Captivate version 11.5.5 and earlier are affected by CVE-2021-36002.
CVE-2021-36002 requires local access by an attacker to exploit the vulnerability.