CVE-2025-24794

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Jan 29, 2025
CWE ID 502

Summary

CVE-2025-24794 is a local privilege escalation vulnerability affecting versions 2.7.12 through 3.13.0 of the Snowflake Connector for Python. The weakness lies in the use of pickle as the serialization format for the Online Certificate Status Protocol (OCSP) response cache. An attacker who manages to manipulate the cache can execute arbitrary code, elevating their privileges within the Python application. Snowflake addressed this issue in version 3.13.1 by implementing more secure serialization methods. Developers using the Snowflake Connector for Python are advised to upgrade to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share