First published: Tue Nov 23 2021(Updated: )
Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Creative Cloud Desktop Application | <=5.5 | |
Apple macOS | ||
All of | ||
Adobe Creative Cloud Desktop Application | <=5.5 | |
Apple macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the privilege escalation vulnerability in Adobe Creative Cloud is CVE-2021-43019.
CVE-2021-43019 has a severity rating of 7.8 (critical).
CVE-2021-43019 affects Adobe Creative Cloud version 5.5 (and earlier) by enabling an unauthenticated attacker to remove files and escalate privileges under the context of SYSTEM.
An attacker can exploit CVE-2021-43019 by leveraging the vulnerability in the resources leveraged by the Setup.exe service.
No, Apple macOS is not affected by CVE-2021-43019.
To mitigate the risk of CVE-2021-43019, update Adobe Creative Cloud to a version that is not affected by the vulnerability.
You can find more information about CVE-2021-43019 on the Adobe Security Bulletin APSB21-111 at the following link: https://helpx.adobe.com/security/products/creative-cloud/apsb21-111.html