CVE-2020-24447 is an uncontrolled search path vulnerability affecting Adobe Lightroom Classic version 10.0 and earlier on Windows, allowing for arbitrary code execution. This high-severity vulnerability (CVSS 7.0) requires user interaction, specifically opening a malicious file, to exploit. While no public exploit code or active exploitation has been observed, its potential impact includes full compromise of the user's system. Community discussion and media coverage indicate limited attention to this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0CPE matchmatch criteria | cpe:2.3:a:adobe:lightroom:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.0 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.