CVE-2016-4158: Adobe Creative Cloud

High severity, CVSS 7.3. EPSS: 3% chance of exploitation in the next 30 days.

Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.7.0.272 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

Affected products

  • Adobe Creative Cloud: up to and including 3.6.0.248
  • Microsoft Windows: any version

Published 2016-06-16. Last modified 2026-06-17.