CVE-2024-30314

Published May 16, 2024

Last updated 6 months ago

Overview

Description
Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker. Exploitation of this issue does require user interaction.
Source
psirt@adobe.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
8.2
Impact score
5.8
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Severity
HIGH

Weaknesses

psirt@adobe.com
CWE-78

Social media

Hype score
Not currently trending