CRITICAL
flash-plugin: Arbitrary Code Execution vulnerability (APSB20-30)
Published Jun 12, 2020
9.8
CRITICALCVSS 3.1
EPSS 7.56%
Description
Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected products
-
- Version 32.0.0.371 and earlier, 32.0.0.371 and earlier, and 32.0.0.330 and earlier versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Adobe | Adobe Flash Player | n/a |
|
Configuration 1
AND
- ≤ 32.0.0.371
Configuration 2
AND
- ≤ 32.0.0.371
Configuration 3
AND
OR
- ≤ 32.0.0.330
- ≤ 32.0.0.330
Running on/with
OR
- n/a
- n/a
No data.
Red Hat Enterprise Linux 6 Supplementary
flash-plugin-0:32.0.0.387-1.el6_10
Fixed · RHSA-2020:2547
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 Supplementary | flash-plugin-0:32.0.0.387-1.el6_10 | Fixed | RHSA-2020:2547 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://access.redhat.com/security/cve/CVE-2020-9633 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1845700 Issue Tracking
- https://helpx.adobe.com/security/products/flash-player/apsb20-30.html x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-9633
- https://security.gentoo.org/glsa/202006-09 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-9633
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-9633 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1845700 | Issue Tracking | |
| https://helpx.adobe.com/security/products/flash-player/apsb20-30.html | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-9633 | ||
| https://security.gentoo.org/glsa/202006-09 | vendor-advisoryx_refsource_GENTOOThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2020-9633 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Jun 12, 2020
Updated Aug 4, 2024
Reserved Mar 2, 2020
Link CVE-2020-9633
CISA Vulnrichment
Updated n/a