Adobe Creative Cloud Unquoted Service Path in CCXProcess
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by an Unquoted Service Path vulnerability in CCXProcess that could allow an attacker to achieve arbitrary code execution in the process of the current user. Exploitation of this issue requires user interaction
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
Adobe · Creative Cloud (desktop component)