CVE-2018-4991 describes an improper certificate validation vulnerability in Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier. This critical vulnerability, with a CVSS score of 9.8, allows for a security bypass due to its network-based attack vector, low complexity, and potential for complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation or publicly available exploit code, the vulnerability has garnered significant community attention with 11 mentions and one media article.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.4.1.298CPE matchmatch criteria | cpe:2.3:a:adobe:creative_cloud:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.