Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer. An authenticated attacker with root privileges could leverage this vulnerability to achieve denial of service by planting a malicious file on the victim's local machine. User interaction is required before product installation to abuse this vulnerability.
References
Link | Resource |
---|---|
https://helpx.adobe.com/security/products/creative-cloud/apsb21-111.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
02 Feb 2022, 13:05
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 4.2 |
28 Jan 2022, 22:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer. An authenticated attacker with root privileges could leverage this vulnerability to achieve denial of service by planting a malicious file on the victim's local machine. User interaction is required before product installation to abuse this vulnerability. | |
CWE |
23 Nov 2021, 01:55
Type | Values Removed | Values Added |
---|---|---|
CWE | NVD-CWE-Other | |
References | (MISC) https://helpx.adobe.com/security/products/creative-cloud/apsb21-111.html - Patch, Vendor Advisory | |
CPE | cpe:2.3:a:adobe:creative_cloud_desktop_application:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 3.5
v3 : 5.7 |
19 Nov 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.2 |
18 Nov 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-11-18 19:15
Updated : 2024-02-04 22:08
NVD link : CVE-2021-43017
Mitre link : CVE-2021-43017
CVE.ORG link : CVE-2021-43017
JSON object : View
Products Affected
apple
- macos
adobe
- creative_cloud_desktop_application
CWE