Bulletin ID
Security updates available for Creative Cloud Desktop Application | APSB19-11
|
|
Date Published |
Priority |
|---|---|---|
|
APSB19-11 |
February 12, 2019 |
3 |
Summary
Adobe has released a security update for the Creative Cloud Desktop Application installer for Windows. This update resolves an insecure library loading vulnerability in the installer that could lead to privilege escalation.
Affected versions
|
Product |
Affected version |
Platform |
|
Creative Cloud Desktop Application (installer) |
4.7.0.400 and earlier versions |
Windows |
Solution
Adobe categorizes this update with the following priority rating and recommends users update their installation to the newest version:
|
Product |
Updated version |
Platform |
Priority rating |
Availability |
|
Creative Cloud Desktop Application (installer) |
4.8.0.410 |
Windows |
3 |
Vulnerability Details
|
Vulnerability Category |
Vulnerability Impact |
Severity |
CVE Numbers |
|---|---|---|---|
|
Insecure Library Loading (DLL hijacking) |
Privilege Escalation |
Important |
CVE-2019-7093 |
Acknowledgments
Adobe would like to thank Tomohisa Hasegawa of Canon Marketing Japan Inc. (CVE-2019-7093) for reporting this issue and for working with Adobe to help protect our customers.