Home
HIGH: 7.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/S:N/AU:N/R:U/V:D/RE:LDefault status
unaffected
Any version before 16.3.0.0407
affected
Description
Path traversal in Google Web Designer's template handling versions prior to 16.3.0.0407 on Windows allows attacker to achieve remote code execution by tricking users into downloading a malicious ad template
Problem types
CWE-20 Improper Input Validation
Product status
Any version before 16.3.0.0407
Credits
Bálint Magyar
References
balintmagyar.com/...-traversal-client-side-rce-cve-2025-4613