CVE-2017-3006
published 2017-04-12CVE-2017-3006: Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud…
PriorityP260high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EXPLOIT
EPSS
10.82%
95.3th percentile
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | creative_cloud | <= 3.9.5.353 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for unexpected writes or replacements of libifcoremd.dll or libmmd.dll under the Adobe 32-bit Photoshop DLLs directory by non-administrative, non-SYSTEM users (Authenticated Users have (C) change rights). ↗
- →Alert on DLL hijacking attempts where libifcoremd.dll is replaced in 'C:\Program Files (x86)\Common Files\Adobe\32 bit Photoshop dlls\' — the exploit instructs attackers to replace the existing file and wait for it to be loaded. ↗
- →Detect suspicious DLL loads from 'C:\Program Files (x86)\Common Files\Adobe\32 bit Photoshop dlls\' where the DLL was recently modified by a non-privileged user process. ↗
- →Monitor write access to the Adobe Startup Scripts CC directory, particularly photoshop.jsx, which is also writable by Authenticated Users. ↗
- ·The vulnerability is local exploitation only — no remote attack vector exists. Detection should focus on local privilege escalation via DLL planting. ↗
- ·Affected versions are Adobe Thor (Creative Cloud) 3.9.5.353 and earlier; patched in the April 11, 2017 update. Ensure endpoint detections account for legacy unpatched installs. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No writeups or analysis indexed.
http://hyp3rlinx.altervista.org/advisories/ADOBE-CREATIVE-CLOUD-PRIVILEGE-ESCALATION.txthttp://www.securityfocus.com/bid/97555https://helpx.adobe.com/security/products/creative-cloud/apsb17-13.htmlhttps://www.exploit-db.com/exploits/41878/http://hyp3rlinx.altervista.org/advisories/ADOBE-CREATIVE-CLOUD-PRIVILEGE-ESCALATION.txthttp://www.securityfocus.com/bid/97555https://helpx.adobe.com/security/products/creative-cloud/apsb17-13.htmlhttps://www.exploit-db.com/exploits/41878/
2017-04-12
Published