cbcvebase.
CVE-2017-3006
published 2017-04-12

CVE-2017-3006: Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud…

PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
10.82%
95.3th percentile
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.

Affected

1 ranges
VendorProductVersion rangeFixed in
adobecreative_cloud<= 3.9.5.353

Detection & IOCsextracted from sources · hover to see the quote

pathC:\Program Files (x86)\Common Files\Adobe\32 bit Photoshop dlls\libifcoremd.dll
pathC:\Program Files (x86)\Common Files\Adobe\32 bit Photoshop dlls\libmmd.dll
pathC:\Program Files (x86)\Common Files\Adobe\Startup Scripts CC\Adobe Photoshop\photoshop.jsx
  • Monitor for unexpected writes or replacements of libifcoremd.dll or libmmd.dll under the Adobe 32-bit Photoshop DLLs directory by non-administrative, non-SYSTEM users (Authenticated Users have (C) change rights).
  • Alert on DLL hijacking attempts where libifcoremd.dll is replaced in 'C:\Program Files (x86)\Common Files\Adobe\32 bit Photoshop dlls\' — the exploit instructs attackers to replace the existing file and wait for it to be loaded.
  • Detect suspicious DLL loads from 'C:\Program Files (x86)\Common Files\Adobe\32 bit Photoshop dlls\' where the DLL was recently modified by a non-privileged user process.
  • Monitor write access to the Adobe Startup Scripts CC directory, particularly photoshop.jsx, which is also writable by Authenticated Users.
  • ·The vulnerability is local exploitation only — no remote attack vector exists. Detection should focus on local privilege escalation via DLL planting.
  • ·Affected versions are Adobe Thor (Creative Cloud) 3.9.5.353 and earlier; patched in the April 11, 2017 update. Ensure endpoint detections account for legacy unpatched installs.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.