Impact
Adobe Photoshop Installer was impacted by an uncontrolled search path element flaw that could allow arbitrary code execution by the current user. During the installation process, the installer searches for required components and may load a malicious library that an attacker places in a directory prioritized in the search path. This vulnerability, identified as CWE‑427, requires the victim to run the installer, meaning user interaction is necessary, and its scope is changed.
Affected Systems
Systems impacted are those running Adobe Photoshop Installer from Adobe. No specific version information is supplied; users who routinely download and run the installer are potentially exposed.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. Exploitation requires user interaction; the attacker must persuade a user to execute the installer on the target machine. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, but the high severity score suggests that the vulnerability can be leveraged for significant damage.
OpenCVE Enrichment