CVE-2024-34116
HIGHCreative Cloud Desktop <6.1.0.587 - Code Injection
Title source: llmDescription
Creative Cloud Desktop versions 6.1.0.587 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in a security feature bypass. An attacker could exploit this vulnerability to load and execute malicious libraries, leading to arbitrary file delete. Exploitation of this issue requires user interaction.
Scores
CVSS v3
7.1
EPSS
0.0003
EPSS Percentile
8.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Classification
CWE
CWE-427
Status
published
Affected Products (1)
adobe/creative_cloud_desktop_application
< 6.2.0.554
Timeline
Published
Jun 13, 2024
Tracked Since
Feb 18, 2026