Adobe Lightroom Desktop Vulnerable to Arbitrary Code Execution via Untrusted Search Path
CVE-2024-20754
7.8HIGH
What is CVE-2024-20754?
The vulnerability in Adobe Lightroom Desktop allows for an Untrusted Search Path exploitation where an attacker can craft a malicious file that alters the application's search path for critical resources. This may lead to arbitrary code execution under the current user’s context when the compromised file is opened. Mitigation involves ensuring that only trusted paths are used for resource allocation and being vigilant about the files opened within the application.
Affected Version(s)
Lightroom Desktop 0 <= 7.1.2