Impact
A local privilege escalation flaw exists in Sublime Text for Windows up to Build 4192 (Sublime Text 4) and Build 3207 (Sublime Text 3). Unprivileged users can place a malicious DLL in the user‑writable staging directory under %LOCALAPPDATA%, mark it read‑only to prevent cleanup, and then trigger the elevated installer which copies the DLL into the protected installation folder. As the application launches, the DLL executes with the privileges of the higher‑privileged user, allowing arbitrary code execution. This gives an attacker control over the target system while remaining on the local machine.
Affected Systems
Sublime HQ Pty Ltd’s Sublime Text 3 and Sublime Text 4, specifically builds 3207 and 4192. Users running these versions are susceptible unless they have updated past these builds.
Risk and Exploitability
The CVSS score of 7 indicates significant risk. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known mass exploitation yet. The attack requires local access and the ability to place files in the staging directory, but does not require additional privileges to initiate. Once the malicious DLL is copied, the code executes under elevated rights, making the vulnerability highly damaging to confidentiality, integrity, and availability of the affected machine.
OpenCVE Enrichment