#VU112017 Untrusted search path in snowflake-jdbc - CVE-2025-24789
Published: June 27, 2025
snowflake-jdbc
Snowflake Computing (snowflakedb)
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version, when EXTERNALBROWSER authentication method is used on Windows.