Vulnerability Description
Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could result in a local user with permissions to write to the file system running system commands with administrator privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Dreamweaver | <= 20.2 |
| Apple | Macos | - |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://helpx.adobe.com/security/products/dreamweaver/apsb20-55.htmlPatchVendor Advisory
- https://helpx.adobe.com/security/products/dreamweaver/apsb20-55.htmlPatchVendor Advisory
FAQ
What is CVE-2020-24425?
CVE-2020-24425 is a vulnerability with a CVSS score of 7.5 (HIGH). Dreamweaver version 20.2 (and earlier) is affected by an uncontrolled search path element vulnerability that could lead to privilege escalation. Successful exploitation could result in a local user wi...
How severe is CVE-2020-24425?
CVE-2020-24425 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-24425?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Dreamweaver, Apple Macos, Microsoft Windows.