CVE-2021-43017

MEDIUM

Adobe Creative Cloud Desktop Application < 5.5 - Authenticated Denial of Service via Malicious File Planting

Title source: llm
STIX 2.1

Description

Adobe Creative Cloud version 5.5 (and earlier) are affected by an Application denial of service vulnerability in the Creative Cloud Desktop installer. An authenticated attacker with root privileges could leverage this vulnerability to achieve denial of service by planting a malicious file on the victim's local machine. User interaction is required before product installation to abuse this vulnerability.

References (1)

Core 1
Core References

Scores

CVSS v3 4.2
EPSS 0.0113
EPSS Percentile 62.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-379
Status published
Products (1)
adobe/creative_cloud_desktop_application < 5.5
Published Nov 18, 2021
Tracked Since Feb 18, 2026