Risk | Low |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2018-12829 |
CWE-ID | CWE-295 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Creative Cloud Desktop Application Universal components / Libraries / Software for developers |
Vendor | Adobe |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU14539
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2018-12829
CWE-ID:
CWE-295 - Improper Certificate Validation
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists due to improper certificate validation. A local attacker can supply specially crafted certificate, gain elevated privileges and perform further attacks.
Update to version 4.6.1.
Vulnerable software versionsCreative Cloud Desktop Application: 4.5.0.324 - 4.6.0.384
CPE2.3 External linkshttp://helpx.adobe.com/security/products/creative-cloud/apsb18-32.html
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?