Home/Product/adobe creative cloud
Product

adobe creative cloud

24 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-64896
< 6.8.0.821
Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Per
5.5MEDIUM
CVE-2025-54271
< 6.8.0.821
Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerab
5.6MEDIUM
CVE-2023-26358
< 5.10
Creative Cloud version 5.9.1 (and earlier) is affected by an Untrusted Search Path vulnerability that might allow attackers to exe
8.6HIGH
CVE-2021-28581
<= 5.3
Adobe Creative Cloud Desktop 3.5 (and earlier) is affected by an uncontrolled search path vulnerability that could result in eleva
7.3HIGH
CVE-2020-24422
<= 2.1
Adobe Creative Cloud Desktop Application version 5.2 (and earlier) and 2.1 (and earlier) for Windows is affected by an uncontrolle
7.0HIGH
CVE-2020-9669
<= 5.1
Adobe Creative Cloud Desktop Application versions 5.1 and earlier have a lack of exploit mitigations vulnerability. Successful exp
9.8CRITICAL
CVE-2020-3808
<= 5.0
Creative Cloud Desktop Application versions 5.0 and earlier have a time-of-check to time-of-use (toctou) race condition vulnerabil
5.9MEDIUM
CVE-2019-8236
<= 4.6.1
Creative Cloud Desktop Application version 4.6.1 and earlier versions have Security Bypass vulnerability. Successful exploitation
9.8CRITICAL
CVE-2019-8063
<= 4.6.1
Creative Cloud Desktop Application 4.6.1 and earlier versions have an insecure transmission of sensitive data vulnerability. Succe
7.5HIGH
CVE-2019-7959
<= 4.6.1
Creative Cloud Desktop Application versions 4.6.1 and earlier have a using components with known vulnerabilities vulnerability. Su
9.8CRITICAL
CVE-2019-7958
<= 4.6.1
Creative Cloud Desktop Application versions 4.6.1 and earlier have an insecure inherited permissions vulnerability. Successful exp
9.8CRITICAL
CVE-2019-7957
<= 4.6.1
Creative Cloud Desktop Application versions 4.6.1 and earlier have a security bypass vulnerability. Successful exploitation could
7.5HIGH
CVE-2019-7093
<= 4.7.0.400
Creative Cloud Desktop Application (installer) versions 4.7.0.400 and earlier have an insecure library loading (dll hijacking) vul
7.8HIGH
CVE-2018-5003
< 4.5.5.342
Adobe Creative Cloud Desktop Application before 4.5.5.342 (installer) has an insecure library loading (dll hijacking) vulnerabilit
7.8HIGH
CVE-2018-12829
< 4.6.1
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitatio
9.8CRITICAL
CVE-2018-4992
<= 4.4.1.298
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vulnerabilit
7.8HIGH
CVE-2018-4991
<= 4.4.1.298
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulner
9.8CRITICAL
CVE-2018-4873
<= 4.4.1.298
Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnerability. Su
7.8HIGH
CVE-2017-3007
<= 3.9.5.353
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability in the directory search path used to find resources, related to Cre
7.8HIGH
CVE-2017-3006
<= 3.9.5.353
Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the inst
8.8HIGH
CVE-2016-6935
<= 3.7.0.272
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local us
7.8HIGH
CVE-2016-4158
<= 3.6.0.248
Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local us
7.3HIGH
CVE-2016-4157
<= 3.6.0.248
Untrusted search path vulnerability in the installer in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allow
7.3HIGH
CVE-2016-1034
<= 3.5.1.209
The Sync Process in the JavaScript API for Creative Cloud Libraries in Adobe Creative Cloud Desktop Application before 3.6.0.244 a
9.1CRITICAL
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin