Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/93489 | vdb entry |
https://helpx.adobe.com/security/products/creative-cloud/apsb16-34.html | vendor advisory |