CVE-2016-6935: Adobe Creative Cloud

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Unquoted Windows search path vulnerability in Adobe Creative Cloud Desktop Application before 3.8.0.310 on Windows allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.

Affected products

  • Adobe Creative Cloud: up to and including 3.7.0.272

Published 2016-10-13. Last modified 2026-06-17.