CVE-2016-1034
Adobe Creative Cloud Node.js Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The Sync Process in the JavaScript API for Creative Cloud Libraries in Adobe Creative Cloud Desktop Application before 3.6.0.244 allows remote attackers to read or write to arbitrary files via unspecified vectors.
El Sync Process en la API JavaScript para Creative Cloud Libraries en Adobe Creative Cloud Desktop Application en versiones anteriores a 3.6.0.244 permite a atacantes remotos leer o escribir en archivos arbitrarios a través de vectores no especificados.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Adobe Creative Cloud. Authentication is not required to exploit this vulnerability.
The application exposes a services that listens on a random TCP port. The lack of authentication in the exposed service allows remote users to execute various methods from the API exposed by this service. An attacker can leverage this to execute code under the context of the current user.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-12-22 CVE Reserved
- 2016-04-12 CVE Published
- 2024-08-05 CVE Updated
- 2024-12-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-16-235 | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/creative-cloud/apsb16-11.html | 2016-12-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Creative Cloud Search vendor "Adobe" for product "Creative Cloud" | <= 3.5.1.209 Search vendor "Adobe" for product "Creative Cloud" and version " <= 3.5.1.209" | - |
Affected
|