peter bassill · operator
$ cve CVE-2020-9633 JSON

CVE-2020-9633

9.8
CRITICAL · CVSS 3.1 · EPSS 7.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.56% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-416
On CISA KEVno
Public exploitnone known
Published2020-06-12
Last modified2026-06-17

Affected (8)

VendorProduct
adobeflash player
adobeflash player desktop runtime
applemacos
googlechrome os
linuxlinux kernel
microsoftwindows
microsoftwindows 10
microsoftwindows 8.1

References

→ the Explorer  ·  watch your stack  ·  NVD