Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-54271

Опубликовано: 15 окт. 2025
Источник: nvd
CVSS3: 5.6
EPSS Низкий

Описание

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:adobe:creative_cloud:*:*:*:*:*:*:*:*
Версия до 6.8.0.821 (исключая)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

EPSS

Процентиль: 4%
0.00019
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 5.6
github
4 месяца назад

Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction.

EPSS

Процентиль: 4%
0.00019
Низкий

5.6 Medium

CVSS3

Дефекты

CWE-367