Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43019

Опубликовано: 23 нояб. 2021
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:adobe:creative_cloud_desktop_application:*:*:*:*:*:*:*:*
Версия до 5.5 (включая)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00542
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-732
CWE-732

Связанные уязвимости

CVSS3: 7.8
github
около 4 лет назад

Adobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe service. An unauthenticated attacker could leverage this vulnerability to remove files and escalate privileges under the context of SYSTEM . An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability on the product installer. User interaction is required before product installation to abuse this vulnerability.

EPSS

Процентиль: 67%
0.00542
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-732
CWE-732