Bulletin ID
Security update available for Adobe Creative Cloud Desktop Application | APSB21-76
|
Date Published |
Priority |
---|---|---|
ASPB21-76 |
September 14, 2021 |
3 |
Summary
Adobe has released an update for the Creative Cloud Desktop for Windows and macOS. This update includes a fix for a critical vulnerability that could lead to arbitrary file system read in the context of current user.
Affected versions
Product |
Affected version |
Platform |
Creative Cloud Desktop Application |
5.4 and earlier version |
macOS |
Solution
Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version:
Product |
Updated version |
Platform |
Priority rating |
Availability |
Creative Cloud Desktop Application |
5.5 |
macOS |
3 |
Vulnerability Details
Vulnerability Category |
Vulnerability Impact |
Severity |
CVSS base score |
CVE Numbers |
|
---|---|---|---|---|---|
Creation of Temporary File in Directory with Incorrect Permissions (CWE-379) |
Arbitrary file system write |
Critical |
7.4 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H |
CVE-2021-28613 |
Acknowledgments
Adobe would like to thank CQY of Topsec Alpha Team (yjdfy) for reporting this issue and for working with Adobe to help protect our customers.
Revisions
September 20, 2021: Updated CVSS base score and CVSS vector for CVE-2021-28613.
September 27, 2021: Updated solution to only specify affected platform is macOS.
January 19th, 2022: Updated CVSS details for CVE-2021-28613
For more information, visit https://helpx.adobe.com/security.html , or email PSIRT@adobe.com.