Impact
Creative Cloud Desktop contains a Time‑of‑Check Time‑of‑Use (TOCTOU) race condition that can lead to arbitrary code execution in the context of the current user. The flaw is a CWE‑367 weakness; it allows an attacker to execute malicious code without requiring the user to interact with the application. The impact is a change of scope and a compromise of system integrity, enabling full code execution privileges for the victim's account.
Affected Systems
Adobe’s Creative Cloud Desktop application is impacted. The advisory does not list specific application versions, so users should review the installed Adobe software list to verify whether their version is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score of less than 1 % suggests a low likelihood of exploitation in the wild, and the vulnerability is not present in the CISA KEV catalog. Based on the advisory, the attack most likely requires conditions that are not directly under the attacker’s control, implying a local or constrained remote scenario. Thus, while the potential damage from the vulnerability is significant, the real‑world risk remains low under the current conditions.
OpenCVE Enrichment