Privilege Escalation Vulnerability in Snowflake JDBC Driver for Windows
CVE-2025-24789

7.8HIGH

Key Information:

Vendor
CVE Published:
29 January 2025

What is CVE-2025-24789?

A significant vulnerability has been identified in the Snowflake JDBC Driver, affecting versions 3.2.3 through 3.21.0 on Windows systems. The issue arises when the EXTERNALBROWSER authentication method is utilized, allowing malicious actors with write access to a directory listed in the %PATH% to escalate privileges to the user executing the vulnerable version of the JDBC Driver. Snowflake has addressed this vulnerability in version 3.22.0, underscoring the importance of updating to secure your applications.

Affected Version(s)

snowflake-jdbc >= 3.2.3, < 3.22.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-24789 : Privilege Escalation Vulnerability in Snowflake JDBC Driver for Windows