Aller au contenu

Fiche vulnérabilité

CVE-2022-23202 : faille élevée adobe creative cloud desktop application (CVSS 7.0)

Description

Adobe Creative Cloud Desktop version 2.7.0.13 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must download a malicious DLL file. The attacker has to deliver the DLL on the same folder as the installer which makes it as a high complexity attack vector.

En bref

Sévérité
Élevée (CVSS 7.0)
Vecteur CVSS
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
16 févr. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • adobe creative cloud desktop application

Références

Rechercher une autre vulnérabilité dans la base CVE