CVE-2020-3757

CWE-8435 documents5 sources
Severity
8.8HIGH
EPSS
5.4%
top 9.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13
Latest updateMay 24

Description

Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

NVDadobe/flash_player< 32.0.0.321+3
CVEListV5adobe/adobe_flash_player32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255  and earlier versions

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pcc6-9jm9-hfp4: Adobe Flash Player versions 322022-05-24
CVEList
CVE-2020-3757: Adobe Flash Player versions 322020-02-13

📋Vendor Advisories

1
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB20-06)2020-02-11

💬Community

1
Bugzilla
CVE-2020-3757 flash-plugin: Arbitrary Code Execution vulnerability (APSB20-06)2020-02-11
CVE-2020-3757 (HIGH CVSS 8.8) | Adobe Flash Player versions 32.0.0. | cvebase.io