Impact
An Improper Access Control flaw (CWE-284) in Adobe Dreamweaver Desktop versions 21.7 and earlier could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code by having a victim open a malicious file, as the flaw requires user interaction. The vulnerability also changes scope, meaning that operations originally confined to certain directories can now access higher-level directories, potentially allowing the attacker to reach further into the local file system.
Affected Systems
Adobe Dreamweaver Desktop versions 21.7 and earlier are affected. The application runs under the user’s account, so the files it can read depend on that account’s permissions. Files or directories normally outside the designated access scope can be accessed if the user opens a malicious file.
Risk and Exploitability
The CVSS score of 8.6 indicates a high‑severity risk. The EPSS score is low (<1%), and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there is currently no widespread exploitation data. Attackers must employ social engineering to convince a user to open a malicious file, after which arbitrary code execution is possible. The scope change enlarges the attacker’s reach within the local file system, potentially allowing the attacker to run privileged code and access sensitive data.
OpenCVE Enrichment