CVE-2020-0570: High severity Qt QT vulnerability
Last updated 25 August 2025
Other sources
QLibrary on certain x86 machines, would search for certain libraries and plugins relative to current working directory of the application, which allows an attacker that can place files in the file system and influence the working directory of Qt-based applications to load and execute malicious code.
Upstream Patch:
https://code.qt.io/cgit/qt/qtbase.git/commit/?id=e6f1fde24f77f63fb16b2df239f82a89d2bf05dd
— Red Hat
Uncontrolled search path in the QT Library before 5.14.0, 5.12.7 and 5.9.10 may allow an authenticated user to potentially enable elevation of privilege via local access.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/qtto a version that resolves this vulnerability.Fixed in 5.14.0 - Upgrade
Upgrade
redhat/qtto a version that resolves this vulnerability.Fixed in 5.12.7 - Upgrade
Upgrade
redhat/qtto a version that resolves this vulnerability.Fixed in 5.9.10 - Upgrade
Upgrade
debian/qtbase-opensource-srcto a version that resolves this vulnerability.Fixed in 5.15.2+dfsg-9+deb11u1Fixed in 5.15.2+dfsg-9+deb11u2Fixed in 5.15.8+dfsg-11+deb12u3Fixed in 5.15.15+dfsg-6Fixed in 5.15.17+dfsg-7 - Upgrade
Upgrade
Qt QLibraryto a version that resolves this vulnerability.Fixed in 5.14.0 - Upgrade
Upgrade
Qt QLibraryto a version that resolves this vulnerability.Fixed in 5.12.7 - Upgrade
Upgrade
Qt QLibraryto a version that resolves this vulnerability.Fixed in 5.9.10
Event History
Frequently Asked Questions
What is CVE-2020-0570?
CVE-2020-0570 is a vulnerability in the QT Library before versions 5.14.0, 5.12.7, and 5.9.10 that allows an authenticated user to potentially enable elevation of privilege via local access.
How severe is CVE-2020-0570?
CVE-2020-0570 has a severity rating of 7.3, which is considered high.
Which software versions are affected by CVE-2020-0570?
The QT Library versions before 5.14.0, 5.12.7, and 5.9.10 are affected by CVE-2020-0570.
How can I fix CVE-2020-0570?
To fix CVE-2020-0570, update the QT Library to version 5.14.0 or higher.
Where can I find more information about CVE-2020-0570?
You can find more information about CVE-2020-0570 on the MITRE CVE website and the QT Project mailing list.