CVE-2021-21078

MEDIUM

Adobe Creative Cloud Desktop App <5.3 - RCE

Title source: llm
STIX 2.1

Description

Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this issue requires user interaction

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0108
EPSS Percentile 60.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (1)
adobe/creative_cloud_desktop_application < 5.3
Published Mar 12, 2021
Tracked Since Feb 18, 2026