Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-23202

Опубликовано: 16 фев. 2022
Источник: nvd
CVSS3: 7
CVSS2: 5.1
EPSS Низкий

Описание

Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The attacker has to deliver the DLL on the same folder as the installer which makes it as a high complexity attack vector.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:adobe:creative_cloud_desktop_application:*:*:*:*:*:*:*:*
Версия до 2.7.0.13 (включая)

EPSS

Процентиль: 91%
0.07288
Низкий

7 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-427

Связанные уязвимости

github
почти 4 года назад

Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The attacker has to deliver the DLL on the same folder as the installer which makes it as a high complexity attack vector.

CVSS3: 7
fstec
почти 4 года назад

Уязвимость приложения графического редактора для рабочего стола Adobe Creative Cloud Desktop Application, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 91%
0.07288
Низкий

7 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-427