Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnerability. Successful exploitation could lead to local privilege escalation.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/104103 | vdb entry third party advisory |
http://www.securitytracker.com/id/1040860 | vdb entry third party advisory |
https://helpx.adobe.com/security/products/creative-cloud/apsb18-12.html | vendor advisory |