CVE-2025-64896 Details
Description
Creative Cloud Desktop versions 6.4.0.361 and earlier are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to disrupt the application's functionality by manipulating temporary files. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
A vulnerability exists in the Adobe Creative Cloud Desktop Application for macOS, specifically in versions through 6.4.0.361. This issue involves the creation of temporary files in a directory with incorrect permissions, potentially leading to a denial-of-service condition. An attacker could disrupt the application's functionality by manipulating these temporary files. Exploitation of this vulnerability requires user interaction, as the victim must open a malicious file.
Users are advised to update the Creative Cloud Desktop Application to version 6.8.0.821. This update is available through the Adobe Download Center.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 9, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/creative-cloud/apsb25-120.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-379 | Creation of Temporary File in Directory with Insecure Permissions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe creative cloud | < 6.8.0.821 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 12, 2025 | Initial Analysis | [email protected] |
| Dec 9, 2025 | New CVE Received | [email protected] |