Adobe Creative Cloud < 6.8.0.821 Arbitrary file system write (APSB25-95) (macOS)

medium Nessus Plugin ID 270656

Synopsis

The Adobe Creative Cloud instance installed on the remote host is affected by an arbitrary file system write vulnerability.

Description

The version of Adobe Creative Cloud installed on the remote macOS host is prior to 6.8.0.821. It is, therefore, affected by a vulnerability as referenced in the APSB25-95 advisory.

- Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction. (CVE-2025-54271)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Adobe Creative Cloud version 6.8.0.821 or later.

See Also

http://www.nessus.org/u?6628c099

Plugin Details

Severity: Medium

ID: 270656

File Name: macos_adobe_creative_cloud_apsb25-95.nasl

Version: 1.2

Type: local

Agent: macosx

Published: 10/16/2025

Updated: 10/17/2025

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.4

CVSS v2

Risk Factor: Low

Base Score: 3.8

Temporal Score: 2.8

Vector: CVSS2#AV:L/AC:H/Au:S/C:N/I:C/A:N

CVSS Score Source: CVE-2025-54271

CVSS v3

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.9

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:creative_cloud

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, installed_sw/Creative Cloud

Exploit Ease: No known exploits are available

Patch Publication Date: 10/14/2025

Vulnerability Publication Date: 10/14/2025

Reference Information

CVE: CVE-2025-54271

CWE: 367

IAVA: 2025-A-0746