CVE-2020-24422 is an uncontrolled search path vulnerability in Adobe Creative Cloud Desktop Application versions 5.2 and earlier (Windows) and 2.1 and earlier (Windows), allowing arbitrary code execution with current user privileges. Rated 7.8 HIGH on CVSS, exploitation requires user interaction to open a malicious file, making it a local attack with low complexity but high impact on confidentiality, integrity, and availability. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness despite no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1CPE matchmatch criteria | cpe:2.3:a:adobe:creative_cloud:*:*:*:*:*:windows:*:* | ||
>= 5.0, <= 5.2CPE matchmatch criteria | cpe:2.3:a:adobe:creative_cloud:*:*:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.