Page 5 of 22 results (0.003 seconds)

CVSS: 7.3EPSS: 0%CPEs: 1EXPL: 0

Untrusted search path vulnerability in the installer in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse resource in an unspecified directory. Vulnerabilidad de búsqueda de ruta no confiable en el instalador en Adobe Creative Cloud Desktop Application en versiones anteriores a 3.7.0.272 en Windows permite a usuarios locales obtener privilegios a través de un recurso Troyano en un directorio no especificado. • https://helpx.adobe.com/security/products/creative-cloud/apsb16-21.html • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 9.4EPSS: 27%CPEs: 1EXPL: 0

The Sync Process in the JavaScript API for Creative Cloud Libraries in Adobe Creative Cloud Desktop Application before 3.6.0.244 allows remote attackers to read or write to arbitrary files via unspecified vectors. El Sync Process en la API JavaScript para Creative Cloud Libraries en Adobe Creative Cloud Desktop Application en versiones anteriores a 3.6.0.244 permite a atacantes remotos leer o escribir en archivos arbitrarios a través de vectores no especificados. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Creative Cloud. Authentication is not required to exploit this vulnerability. The application exposes a services that listens on a random TCP port. The lack of authentication in the exposed service allows remote users to execute various methods from the API exposed by this service. • http://www.zerodayinitiative.com/advisories/ZDI-16-235 https://helpx.adobe.com/security/products/creative-cloud/apsb16-11.html •