First published: Tue Oct 20 2020(Updated: )
Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could result in a local user with permissions to write to the file system running system commands with administrator privileges.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Dreamweaver | <=20.2 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24425 is a vulnerability affecting Dreamweaver version 20.2 and earlier, which allows an attacker to escalate privileges.
The severity of CVE-2020-24425 is high, with a CVSS score of 7.8.
CVE-2020-24425 allows a local user to execute system commands with administrator privileges by exploiting an uncontrolled search path element vulnerability in Dreamweaver.
No, Apple macOS is not affected by CVE-2020-24425.
No, Microsoft Windows is not affected by CVE-2020-24425.
To fix CVE-2020-24425, Adobe recommends updating Dreamweaver to version 20.3 or later.