PT-2025-9078 · Blackmagic Design · Davinci Resolve

·

CVE-2025-1413

·

Published

2025-02-28

·

Updated

2025-02-28

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions DaVinci Resolve versions prior to 19.1.3
Description The issue is related to incorrect file permissions in DaVinci Resolve on MacOS, which can lead to Dylib Hijacking. This inconsistency with standard macOS security practices allows for privilege escalation, where the guest account, other users, and applications can exploit this issue.
Recommendations For versions prior to 19.1.3, update to version 19.1.3 or later to resolve the issue. As a temporary workaround, consider changing the file permissions to drwxr-xr-x to minimize the risk of exploitation. Restrict access to the application for guest accounts and other users to prevent privilege escalation until the update is applied.

Fix

LPE

Incorrect Privilege Assignment

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1413

Affected Products

Davinci Resolve