ZDI-CAN-29588: ZDI-26-419: Adobe Creative Cloud AdobeUpdateService Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Adobe Creative Cloud. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-48272.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29588?
The severity of ZDI-CAN-29588 is rated with a CVSS score of 7.0.
How do I fix ZDI-CAN-29588?
To fix ZDI-CAN-29588, update Adobe Creative Cloud to the latest version provided by Adobe.
What are the potential impacts of exploiting ZDI-CAN-29588?
Exploiting ZDI-CAN-29588 can allow local attackers to escalate privileges on affected installations.
Who is at risk for ZDI-CAN-29588?
Individuals using affected versions of Adobe Creative Cloud are at risk for ZDI-CAN-29588.
Do I need to be a remote attacker to exploit ZDI-CAN-29588?
No, a local attacker must first execute low-privileged code on the target system to exploit ZDI-CAN-29588.