CVE-2016-6935

CWE-4283 documents3 sources
Severity
7.8HIGH
EPSS
0.2%
top 55.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 13
Latest updateMay 17

Description

Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

NVDadobe/creative_cloud3.7.0.272

🔴Vulnerability Details

2
GHSA
GHSA-mhv4-fqqh-2p7m: Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 32022-05-17
CVEList
CVE-2016-6935: Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 32016-10-13
CVE-2016-6935 (HIGH CVSS 7.8) | Unquoted Windows search path vulner | cvebase.io