Privilege Escalation Vulnerability in Snowflake JDBC Driver for Windows
CVE-2025-24789
7.8HIGH
What is CVE-2025-24789?
A significant vulnerability has been identified in the Snowflake JDBC Driver, affecting versions 3.2.3 through 3.21.0 on Windows systems. The issue arises when the EXTERNALBROWSER authentication method is utilized, allowing malicious actors with write access to a directory listed in the %PATH% to escalate privileges to the user executing the vulnerable version of the JDBC Driver. Snowflake has addressed this vulnerability in version 3.22.0, underscoring the importance of updating to secure your applications.
Affected Version(s)
snowflake-jdbc >= 3.2.3, < 3.22.0