CVE-2025-20767
published 2025-12-02CVE-2025-20767: In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.07%
0.1th percentile
In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4807.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
cisa7.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92w5-q9q3-vh74: In display, there is a possible out of bounds write due to an integer overflow
ghsa_unreviewed·2025-12-02
CVE-2025-20767 [HIGH] CWE-787 GHSA-92w5-q9q3-vh74: In display, there is a possible out of bounds write due to an integer overflow
In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4807.
CISA
Adobe ColdFusion Improper Access Control Vulnerability
cisa·2024-12-16·CVSS 7.4
CVE-2024-20767 [HIGH] CWE-284 Adobe ColdFusion Improper Access Control Vulnerability
Vulnerability: Adobe ColdFusion Improper Access Control Vulnerability
Affected: Adobe ColdFusion
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://helpx.adobe.com/security/products/coldfusion/apsb24-14.html ; https://nvd.nist.gov/vuln/detail/CVE-2024-20767
Remediation Due Date: 2025-01-06
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-12-02
Published