Impact
Creative Cloud Desktop contains an uncontrolled search‑path element that allows an attacker to manipulate the directories searched for executables. The flaw can lead to arbitrary code execution in the context of the logged‑in user. The CVE description indicates that exploitation does not require user interaction but depends on conditions beyond the attacker’s control, and the scope is changed.
Affected Systems
Adobe Creative Cloud Desktop is the affected product. No specific version numbers are provided, so all installations of Creative Cloud Desktop are considered vulnerable until Adobe releases a patch.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score being less than 1 % suggests that exploitation is unlikely at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that the likely attack vector is local or requires the attacker to initially influence the environment of the user’s workstation. The change in scope increases the potential breadth of compromise if the external conditions that enable exploitation are satisfied.
OpenCVE Enrichment