CVE-2021-28597

MEDIUM

Adobe Photoshop Elements < 5.3 - Exposure to Wrong Actor

Title source: rule

Description

Adobe Photoshop Elements version 5.2 (and earlier) is affected by an insecure temporary file creation vulnerability. An unauthenticated attacker could leverage this vulnerability to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 31.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-379 CWE-668
Status published

Affected Products (1)

adobe/photoshop_elements < 5.3

Timeline

Published Jun 28, 2021
Tracked Since Feb 18, 2026