CVE-2025-24794
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Summary
CVE-2025-24794 is a local privilege escalation vulnerability affecting versions 2.7.12 through 3.13.0 of the Snowflake Connector for Python. The weakness lies in the use of pickle as the serialization format for the Online Certificate Status Protocol (OCSP) response cache. An attacker who manages to manipulate the cache can execute arbitrary code, elevating their privileges within the Python application. Snowflake addressed this issue in version 3.13.1 by implementing more secure serialization methods. Developers using the Snowflake Connector for Python are advised to upgrade to the latest version to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.