Adobe Photoshop Installer – Uncontrolled Search Path Element (DLL Hijacking) (CVE-2026-48388)
Scope: Adobe Photoshop Installer Component
Severity: High
An uncontrolled search path element vulnerability, commonly known as DLL hijacking, exists within the Adobe Photoshop Installer. The installer searches for dynamic link libraries (DLLs) in an unsafe, predictable order without verifying their exact location. An attacker with local access to a system can exploit this by placing a maliciously crafted DLL into a user-writable directory that the installer queries prior to checking the legitimate Windows system directories. When a user runs the installer, it inadvertently loads and executes the attacker's malicious DLL with the privileges of the executing user—which is typically an administrative account during software installation. This results in arbitrary code execution, full host compromise, credential theft, and persistent backdoor installation. Organizations must update to the latest version of Adobe Photoshop, which includes a patched installer component. Furthermore, users must download software strictly from official Adobe sources, enforce application whitelisting, configure strict DLL search-order controls (e.g., enabling the CWDIllegalInDllSearch registry key), and execute installations using the principle of least privilege.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the NVD Record for CVE-2026-48388 and apply the necessary updates.