CVE-2025-64896
Adobe Creative Cloud vulnerability analysis and mitigation

Overview

CVE-2025-64896 is a temporary file creation vulnerability in Adobe Creative Cloud Desktop affecting versions 6.4.0.361 and earlier. The flaw involves the creation of temporary files in a directory with insecure permissions, which can be exploited by a local attacker to cause application denial-of-service. It was published on December 9, 2025, and a patch was made available shortly after. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (Adobe Advisory, Feedly).

Technical details

The root cause is classified as CWE-379 (Creation of Temporary File in Directory with Insecure Permissions). An attacker can exploit this by manipulating temporary files created by the application in a world-writable or improperly permissioned directory, potentially replacing or corrupting them to disrupt application functionality. The attack vector is local, requires no privileges, but does require user interaction — specifically, the victim must open a malicious file. No public proof-of-concept or detailed technical write-up has been identified at this time (Feedly, Adobe Advisory).

Impact

Successful exploitation results in a denial-of-service condition for the Adobe Creative Cloud Desktop application, disrupting its functionality. There is no impact on confidentiality or integrity — only availability is affected. The scope is limited to the local system and the Creative Cloud Desktop application, with no evidence of lateral movement potential or data exposure risk (Feedly).

Mitigation and workarounds

Adobe has released a fix in Creative Cloud Desktop version 6.8.0.821 and later. Users should update to this version or newer immediately via the Creative Cloud Desktop application or Adobe's official download portal. As an interim measure, users should avoid opening files from untrusted or unknown sources. No configuration-based workaround has been published by Adobe (Adobe Advisory).

Community reactions

Coverage of this vulnerability has been limited to standard security aggregation and patch-tracking platforms such as Tenable (Nessus plugin 277982), VulDB, and Fortress SRM's December 2025 threat update. No notable researcher commentary or significant community discussion has been identified beyond routine patch advisories (Tenable, Fortress SRM).

Additional resources


SourceThis report was generated using AI

Related Adobe Creative Cloud vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-26358HIGH7.8
  • Adobe Creative Cloud logoAdobe Creative Cloud
  • cpe:2.3:a:adobe:creative_cloud
NoYesMar 22, 2023
CVE-2020-24422HIGH7.8
  • Adobe Creative Cloud logoAdobe Creative Cloud
  • cpe:2.3:a:adobe:creative_cloud
NoYesOct 21, 2020
CVE-2021-28581HIGH7.3
  • Adobe Creative Cloud logoAdobe Creative Cloud
  • cpe:2.3:a:adobe:creative_cloud
NoYesSep 08, 2021
CVE-2025-54271MEDIUM5.6
  • Adobe Creative Cloud logoAdobe Creative Cloud
  • cpe:2.3:a:adobe:creative_cloud
NoYesOct 15, 2025
CVE-2025-64896MEDIUM5.5
  • Adobe Creative Cloud logoAdobe Creative Cloud
  • cpe:2.3:a:adobe:creative_cloud
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management