
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64896 is a temporary file creation vulnerability in Adobe Creative Cloud Desktop affecting versions 6.4.0.361 and earlier. The flaw involves the creation of temporary files in a directory with insecure permissions, which can be exploited by a local attacker to cause application denial-of-service. It was published on December 9, 2025, and a patch was made available shortly after. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory, Feedly).
The root cause is classified as CWE-379 (Creation of Temporary File in Directory with Insecure Permissions). An attacker can exploit this by manipulating temporary files created by the application in a world-writable or improperly permissioned directory, potentially replacing or corrupting them to disrupt application functionality. The attack vector is local, requires no privileges, but does require user interaction — specifically, the victim must open a malicious file. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly, Adobe Advisory).
Successful exploitation results in a denial-of-service condition for the Adobe Creative Cloud Desktop application, disrupting its functionality. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the local system and the Creative Cloud Desktop application, with no evidence of lateral movement potential or data exposure risk (Feedly).
Adobe has released a fix in Creative Cloud Desktop version 6.8.0.821 and later. Users should update to this version or newer immediately via the Creative Cloud Desktop application or Adobe's official download portal. As an interim measure, users should avoid opening files from untrusted or unknown sources. No configuration-based workaround has been published by Adobe (Adobe Advisory).
Coverage of this vulnerability has been limited to standard security aggregation and patch-tracking platforms such as Tenable (Nessus plugin 277982), VulDB, and Fortress SRM's December 2025 threat update. No notable researcher commentary or significant community discussion has been identified beyond routine patch advisories (Tenable, Fortress SRM).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."