CVE-2020-9590
published 2020-06-26CVE-2020-9590: Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code…
PriorityP349high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
43.74%
98.6th percentile
Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_dng_software_development_kit | — | — |
| adobe | digital_negative_software_development_kit | <= 1.5 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Threat Source newsletter for May 14, 2020
blogs_talos·2020-05-14
Threat Source newsletter for May 14, 2020
Newsletter compiled by Jon Munshaw.
Welcome to this week’s Threat Source newsletter — the perfect place to get caught up on all things Talos from the past week.
Our main focus this week is on Astaroth. This is a malware family that has been targeting Brazil with a variety of lures, including COVID-19-themed documents, for the past nine to 12 months. Astaroth implements a robust series of anti-analysis/evasion techniques, among the most thorough we've seen recently. We have the full rundown of the threat and our protections against it.
And, as always, we have the latest Threat Roundup where we go through the top threats we saw — and blocked — over the past week.
### Upcoming public engagements
Event: “Dynamic Data Resolver IDA plugin” at NSEC Online
Location: Streaming on Twitch
Date:
Talos
Threat Source newsletter for May 14, 2020
blogs_talos·2020-05-14
Threat Source newsletter for May 14, 2020
## Threat Source newsletter for May 14, 2020
Newsletter compiled by Jon Munshaw.
Welcome to this week’s Threat Source newsletter — the perfect place to get caught up on all things Talos from the past week.
Our main focus this week is on Astaroth. This is a malware family that has been targeting Brazil with a variety of lures, including COVID-19-themed documents, for the past nine to 12 months. Astaroth implements a robust series of anti-analysis/evasion techniques, among the most thorough we've seen recently. We have the full rundown of the threat and our protections against it .
And, as always, we have the latest Threat Roundup where we go through the top threats we saw — and blocked — over the past week.
## Upcoming public engagements
Event: “Dynamic Data Resolver IDA plugin” at NS
2020-06-26
Published