← Vulnerability feed

Vulnerability record · CVE-2021-21069 · published 12 March 2021

CVE-2021-21069: Adobe creative cloud desktop application improper input validation vulnerability

Adobe · Creative Cloud Desktop Application

Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an attacker to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.

7.8 CVSS 3.0 High EPSS 2.5% · top 16.1% CWE-20 · Improper input validation
7.8CVSS 3.0 base score, v2 9.3
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Adobe Creative Cloud Desktop Application version 5.3 (and earlier) is affected by a local privilege escalation vulnerability that could allow an attacker to call functions against the installer to perform high privileged actions. Exploitation of this issue does not require user interaction.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21069 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-9682Adobe creative cloud desktop application link following vulnerabilityAdobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to a…EPSS 4.3%9.8CVE-2020-9670Adobe creative cloud desktop application link following vulnerabilityAdobe Creative Cloud Desktop Application versions 5.1 and earlier have a symlink vulnerability vulnerability. Successful exploitation could lead to p…EPSS 3.6%9.8CVE-2020-9671Adobe creative cloud desktop application incorrect permission assignment vulnerabilityAdobe Creative Cloud Desktop Application versions 5.1 and earlier have an insecure file permissions vulnerability. Successful exploitation could lead…EPSS 4.0%7.8CVE-2026-48344Adobe creative cloud desktop application toctou race condition vulnerabilityCreative Cloud Desktop is affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could result in arbitrary code execution…EPSS 0.17%7.8CVE-2026-48272Adobe creative cloud desktop application uncontrolled search path element vulnerabilityCreative Cloud Desktop is affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context …EPSS 0.23%7.8CVE-2021-43019Adobe creative cloud desktop application incorrect permission assignment vulnerabilityAdobe Creative Cloud version 5.5 (and earlier) are affected by a privilege escalation vulnerability in the resources leveraged by the Setup.exe servi…EPSS 2.2%7.8CVE-2021-28547Adobe creative cloud desktop application improper input validation vulnerabilityAdobe Creative Cloud Desktop Application for macOS version 5.3 (and earlier) is affected by a privilege escalation vulnerability that could allow a n…EPSS 0.52%7.8CVE-2021-28594Adobe creative cloud desktop application uncontrolled search path element vulnerabilityAdobe Creative Cloud Desktop Application (installer) version 2.4 (and earlier) is affected by an Uncontrolled Search Path Element vulnerability. An u…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2021-21069), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.