CVE-2020-17759 is a high-severity vulnerability affecting the Evernote client for Windows 10, 7, and Server 2008, stemming from an issue in its protocol handler. This flaw allows for arbitrary command execution if a user clicks on a specially crafted URL, posing a significant risk to confidentiality, integrity, and availability. With a CVSS score of 8.8, it is easily exploitable over the network with low attack complexity, requiring user interaction. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation are currently reported, and community discussion is minimal, the potential impact remains high.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.17.7CPE matchmatch criteria | cpe:2.3:a:evernote:evernote:6.17.7:*:*:*:*:windows:*:* | ||
6.18CPE matchmatch criteria | cpe:2.3:a:evernote:evernote:6.18:beta2:*:*:*:windows:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.