CVE-2020-9746NULL Pointer Dereference in Adobe Flash Player

Severity
8.8HIGHNVD
CNA7.0
EPSS
1.7%
top 17.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14
Latest updateMay 24

Description

Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDadobe/flash_player< 32.0.0.433+2
CVEListV5adobe/flash_playerunspecified32.0.0.387+2

🔴Vulnerability Details

3
GHSA
GHSA-h82h-rg57-cr4v: Adobe Flash Player version 322022-05-24
CVEList
Exploitable NULL pointer deref could lead to arbitrary code execution2020-10-14
OSV
CVE-2020-9746: Adobe Flash Player version 322020-10-14

📋Vendor Advisories

1
Red Hat
flash-plugin: Arbitrary Code Execution vulnerability (APSB20-58)2020-10-13

💬Community

1
Bugzilla
CVE-2020-9746 flash-plugin: Arbitrary Code Execution vulnerability (APSB20-58)2020-10-13
CVE-2020-9746 — NULL Pointer Dereference in Adobe | cvebase