Adobe Lightroom Desktop Vulnerable to Arbitrary Code Execution via Untrusted Search Path
CVE-2024-20754
7.8HIGH
Summary
The vulnerability in Adobe Lightroom Desktop allows for an Untrusted Search Path exploitation where an attacker can craft a malicious file that alters the application's search path for critical resources. This may lead to arbitrary code execution under the current user’s context when the compromised file is opened. Mitigation involves ensuring that only trusted paths are used for resource allocation and being vigilant about the files opened within the application.
Affected Version(s)
Lightroom Desktop 0 <= 7.1.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved