PT-2025-9078 · Blackmagic Design · Davinci Resolve
Karol Mazurkowi
·
Published
2025-02-28
·
Updated
2025-02-28
·
CVE-2025-1413
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
DaVinci Resolve versions prior to 19.1.3
Description
The issue is related to incorrect file permissions in DaVinci Resolve on MacOS, which can lead to Dylib Hijacking. This inconsistency with standard macOS security practices allows for privilege escalation, where the guest account, other users, and applications can exploit this issue.
Recommendations
For versions prior to 19.1.3, update to version 19.1.3 or later to resolve the issue. As a temporary workaround, consider changing the file permissions to drwxr-xr-x to minimize the risk of exploitation. Restrict access to the application for guest accounts and other users to prevent privilege escalation until the update is applied.
Fix
LPE
Incorrect Privilege Assignment
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Davinci Resolve