7.8
CVE-2026-48344
- EPSS 0.1%
- Veröffentlicht 14.07.2026 20:21:15
- Zuletzt bearbeitet 17.07.2026 03:23:06
- CVE-Watchlists
- Unerledigt
GoCart | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367)
Creative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution in the context of the current user. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction. Scope is changed.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Creative Cloud Desktop Application Version <= 6.9.1.1
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.012 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Adobe | 7.8 | 1.1 | 6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.
https://helpx.adobe.com/security/products/creative-cloud/apsb26-77.html