CVE ID | CVE-2025-1413 |
Publication date | 28 February 2025 |
Vendor | Blackmagic Design Inc |
Product | DaVinci Resolve |
Vulnerable versions | All before 19.1.3 |
Vulnerability type (CWE) | Incorrect Privilege Assignment (CWE-266) |
Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in DaVinci Resolve software and participated in coordination of its disclosure.
DaVinci Resolve application on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. The vulnerability CVE-2025-1413 allows for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation.
This issue affects DaVinci Resolve on MacOS in versions before 19.1.3.
Credits
We thank Karol Mazurek from AFINE for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.