CVE-2025-1413

HIGH

DaVinci Resolve <19.1.3 - Privilege Escalation

Title source: llm
STIX 2.1

Description

DaVinci Resolve on MacOS was found to be installed with incorrect file permissions (rwxrwxrwx). This is inconsistent with standard macOS security practices, where applications should have drwxr-xr-x permissions. Incorrect permissions allow for Dylib Hijacking. Guest account, other users and applications can exploit this vulnerability for privilege escalation. This issue affects DaVinci Resolve on MacOS in versions before 19.1.3.

Scores

CVSS v4 8.4
EPSS 0.0007
EPSS Percentile 22.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (1)
Blackmagic Design Inc/DaVinci Resolve < 19.1.3
Published Feb 28, 2025
Tracked Since Feb 18, 2026