CVE-2020-9667

MEDIUM

Adobe Genuine Service < 6.6 - Authenticated Uncontrolled Search Path Element

Title source: llm
STIX 2.1

Description

Adobe Genuine Service version 6.6 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An authenticated attacker with admin privileges could plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
adobe/genuine_service < 6.6
Published Apr 16, 2021
Tracked Since Feb 18, 2026