Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wxwj-m72v-qhcr

Опубликовано: 24 нояб. 2021
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.

Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.

EPSS

Процентиль: 67%
0.00542
Низкий

7.8 High

CVSS3

Дефекты

CWE-284
CWE-732

Связанные уязвимости

CVSS3: 7.8
nvd
около 4 лет назад

Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.

EPSS

Процентиль: 67%
0.00542
Низкий

7.8 High

CVSS3

Дефекты

CWE-284
CWE-732