CVE-2021-21078
published 2021-03-12CVE-2021-21078: Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an…
PriorityP428medium6.5CVSS 3.1
AVLACLPRHUIRSUCHIHAH
EPSS
1.08%
61.2th percentile
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this issue requires user interaction
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | creative_cloud | unspecified – 5.3 | — |
| adobe | creative_cloud_desktop_application | <= 5.3 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Qualys
March 2021 Patch Tuesday – 82 Vulnerabilities, 10 Critical, Adobe | Qualys
blogs_qualys·2021-03-09·CVSS 7.8
CVE-2021-26411 [HIGH] March 2021 Patch Tuesday – 82 Vulnerabilities, 10 Critical, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 82 vulnerabilities, of which 10 are rated with Critical severity. This follows an out-of-band security update on March 2 to address critical vulnerabilities in Microsoft Exchange. Adobe released patches today for its FrameMaker, Creative Cloud Desktop, and Adobe Connect products.
### Internet Explorer Memory Corruption Vulnerability
Microsoft released patches addressing another 0-day vulnerability (CVE-2021-26411). This is a memory corruption vulnerability in Internet Explorer. This CVE already has a working exploit and is assigned a CVSSv3 base score of 8.8 by the vendor.
### Windows Hyper-V Remote Code Execution (RCE) Vulnerability
Microsoft released patches to fix a RCE vulnerability in Windows Hyper-V (CVE-2021-26867). This vulnerabili
Qualys
March 2021 Patch Tuesday – 82 Vulnerabilities, 10 Critical, Adobe
blogs_qualys·2021-03-09·CVSS 7.8
CVE-2021-26411 [HIGH] March 2021 Patch Tuesday – 82 Vulnerabilities, 10 Critical, Adobe
This month’s Microsoft Patch Tuesday addresses 82 vulnerabilities, of which 10 are rated with Critical severity. This follows an out-of-band security update on March 2 to address critical vulnerabilities in Microsoft Exchange. Adobe released patches today for its FrameMaker, Creative Cloud Desktop, and Adobe Connect products.
## Internet Explorer Memory Corruption Vulnerability
Microsoft released patches addressing another 0-day vulnerability (CVE-2021-26411). This is a memory corruption vulnerability in Internet Explorer. This CVE already has a working exploit and is assigned a CVSSv3 base score of 8.8 by the vendor.
## Windows Hyper-V Remote Code Execution (RCE) Vulnerability
Microsoft released patches to fix a RCE vulnerability in Windows Hyper-V (CVE-2021-26867). This vulnerability
2021-03-12
Published