Adobe Lightroom Desktop Vulnerable to Arbitrary Code Execution via Untrusted Search Path
CVE-2024-20754

7.8HIGH

Key Information:

Vendor
Adobe
Vendor
CVE Published:
18 March 2024

Summary

The vulnerability in Adobe Lightroom Desktop allows for an Untrusted Search Path exploitation where an attacker can craft a malicious file that alters the application's search path for critical resources. This may lead to arbitrary code execution under the current user’s context when the compromised file is opened. Mitigation involves ensuring that only trusted paths are used for resource allocation and being vigilant about the files opened within the application.

Affected Version(s)

Lightroom Desktop 0 <= 7.1.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.