{"id":"CVE-2025-54271","title":"Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write","summary":"Creative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing be…","severity":"medium","cvss":5.6,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N","cwe":["CWE-367"],"vendor":"adobe","product":"creative_cloud","affected":["creative_cloud < 6.8.0.821"],"patched":["creative_cloud 6.8.0.821"],"published":"2025-10-15","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-54271","references":[{"url":"https://helpx.adobe.com/security/products/creative-cloud/apsb25-95.html","label":"psirt@adobe.com"}],"tags":["nvd"],"epss":0.00143,"epssPercentile":0.03093,"ingestedAt":"2026-10-08T11:31:27.441Z","slug":"CVE-2025-54271","body":"## Overview\n\nCreative Cloud Desktop versions 6.7.0.278 and earlier are affected by a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability that could lead to arbitrary file system write. A low-privileged attacker could exploit the timing between the check and use of a resource, potentially allowing unauthorized modifications to files. Exploitation of this issue does not require user interaction.\n\n## Affected\n\n- `creative_cloud < 6.8.0.821`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `creative_cloud 6.8.0.821`","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":30.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}