Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe creative Cloud Desktop Application
|
|
| Vendors & Products |
Adobe creative Cloud Desktop Application
|
Fri, 17 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adobe
Adobe creative Cloud Apple Apple macos |
|
| CPEs | cpe:2.3:a:adobe:creative_cloud:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Adobe
Adobe creative Cloud Apple Apple macos |
Wed, 15 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction. | |
| Title | Creative Cloud Desktop | Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) | |
| Weaknesses | CWE-367 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: adobe
Published:
Updated: 2025-10-15T16:55:45.119Z
Reserved: 2025-07-17T21:15:02.465Z
Link: CVE-2025-54271
Updated: 2025-10-15T16:55:41.844Z
Status : Analyzed
Published: 2025-10-15T17:15:59.333
Modified: 2025-10-17T15:02:54.237
Link: CVE-2025-54271
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:40:57Z