Adobe Premiere Elements Privilege Escalation (APSB22-43) (macOS)

high Nessus Plugin ID 164088

Synopsis

The Adobe Premiere Elements instance installed on the remote host is affected by a privilege escalation vulnerability.

Description

The version of Adobe Premiere Elements installed on the remote macOS host is prior to build 20.0 (20220702.Git.main.e4f8578). It is, therefore, affected by a vulnerability as referenced in the APSB22-43 advisory.

- Adobe Premiere Elements version 2020v20 (and earlier) is affected by an Uncontrolled Search Path Element which could lead to Privilege Escalation. An attacker could leverage this vulnerability to obtain admin using an existing low-privileged user. Exploitation of this issue does not require user interaction.
(CVE-2022-34235)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade Adobe Premiere Elements to build 20.0 (20220702.Git.main.e4f8578) or later.

See Also

http://www.nessus.org/u?5f527f74

Plugin Details

Severity: High

ID: 164088

File Name: macos_adobe_premiere_elems_apsb22-43.nasl

Version: 1.6

Type: local

Agent: macosx

Published: 8/12/2022

Updated: 10/21/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2022-34235

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:adobe:premiere_elements

Required KB Items: Host/local_checks_enabled, Host/MacOSX/Version, installed_sw/Adobe Premiere Elements

Exploit Ease: No known exploits are available

Patch Publication Date: 7/7/2022

Vulnerability Publication Date: 8/9/2022

Reference Information

CVE: CVE-2022-34235

CWE: 427

IAVA: 2022-A-0322