PT-2025-9078 · Blackmagic Design · Davinci Resolve

Karol Mazurkowi

·

Published

2025-02-28

·

Updated

2025-02-28

·

CVE-2025-1413

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions DaVinci Resolve versions prior to 19.1.3
Description The issue is related to incorrect file permissions in DaVinci Resolve on MacOS, which can lead to Dylib Hijacking. This inconsistency with standard macOS security practices allows for privilege escalation, where the guest account, other users, and applications can exploit this issue.
Recommendations For versions prior to 19.1.3, update to version 19.1.3 or later to resolve the issue. As a temporary workaround, consider changing the file permissions to drwxr-xr-x to minimize the risk of exploitation. Restrict access to the application for guest accounts and other users to prevent privilege escalation until the update is applied.

Fix

LPE

Incorrect Privilege Assignment

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2025-1413

Affected Products

Davinci Resolve