CVE-2025-24789 is a privilege escalation vulnerability in the Snowflake JDBC Driver, affecting versions 3.2.3 through 3.21.0 on Windows when using the EXTERNALBROWSER authentication method. An attacker with write access to a directory in the %PATH% can escalate privileges to the user running the driver. With a CVSS score of 7.8 (High), this vulnerability has a low attack complexity and requires local access, but can lead to high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.2.3, < 3.22.0CPE matchmatch criteria | cpe:2.3:a:snowflake:snowflake_jdbc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.