Impact
An Improper Access Control flaw in Adobe Dreamweaver Desktop allows a victim to read files from the local file system that fall outside the intended access scope. The vulnerability requires user interaction: the victim must open a crafted file. Once executed, the application’s read operations succeed and the attacker can retrieve sensitive data. The flaw manifests as a change in scope, meaning that operations originally confined to certain directories can now access higher‑level directories.
Affected Systems
Adobe Dreamweaver Desktop versions 21.7 and earlier are affected by this vulnerability. The application runs under the user’s account, so the files it can read depend on that account’s permissions. Files or directories that are normally outside the designated access scope can be accessed if the user opens a malicious file.
Risk and Exploitability
The CVSS score of 8.2 indicates a high‑severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there is currently no widespread exploitation data. Attackers must employ social engineering to convince a user to open a malicious file, after which arbitrary read of privileged files is possible. The scope change enlarges the attacker’s reach within the local file system, potentially exposing confidential information.
OpenCVE Enrichment