Untrusted Search Path Vulnerability Could Lead to Arbitrary Code Execution
CVE-2024-41865
7.8HIGH
Summary
Adobe Dimension, particularly versions 3.4.11 and earlier, is susceptible to an Untrusted Search Path vulnerability. This flaw allows an attacker to introduce a harmful file into the application's search path, which may lead to the execution of unauthorized code. The exploitation of this vulnerability is contingent upon user interaction, as the system may mistakenly execute the injected file instead of the intended legitimate executable or library. Awareness of this vulnerability is crucial for users to mitigate potential security risks.
Affected Version(s)
Dimension 0 <= 3.4.11
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved