Executive brief
Adobe Creative Cloud Desktop, the management application for Adobe's suite of creative software, is affected by a security vulnerability that could allow an attacker to run unauthorized code on a user's computer. If exploited, an attacker could gain full control over the affected system, potentially leading to data theft or further network compromise. This issue requires the attacker to already have limited access to the machine, but it does not require any interaction from the logged-in user.
Technical details
Adobe Creative Cloud Desktop versions 6.9.1.1 and earlier contain an Uncontrolled Search Path Element vulnerability (CWE-427). The flaw occurs when the application attempts to load a resource or library without a fully qualified path, allowing a local attacker to place a malicious file in a location searched by the application. Successful exploitation requires local access and specific environmental conditions (High Attack Complexity), but does not require user interaction. If triggered, the attacker can execute arbitrary code with the privileges of the current user and potentially escape the application's security scope. Adobe has addressed this in version 6.10.0.252.3.
Affected products
- Adobe Creative Cloud Desktop <= 6.9.1.1
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory