Insecure DLL loading in Creative Cloud Desktop Application - CVE-2021-28594

 

Insecure DLL loading in Creative Cloud Desktop Application - CVE-2021-28594

Published: June 9, 2021


Vulnerability identifier: #VU53961
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-28594
CWE-ID: CWE-427
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to installer for Creative Cloud Desktop loads DLL libraries in an insecure manner. A remote attacker can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into launching the installation file from that directory and execute arbitrary code on victim's system.


Affected software

Creative Cloud Desktop Application

How to mitigate CVE-2021-28594

Install updates from vendor's website.

Creative Cloud Desktop Application - update to 5.4.5.550

External References

Related Security Bulletins