CVE-2020-19725 is a high-severity use-after-free vulnerability in Microsoft Z3 versions prior to 4.8.8, specifically within the pdd_simplifier.cpp file. This flaw can be triggered when the solver attempts to simplify constraints, leading to unexpected memory access. Successful exploitation, which requires user interaction, could result in segmentation faults or arbitrary code execution, posing a significant risk to confidentiality, integrity, and availability. There is currently no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.8.8CPE matchmatch criteria | cpe:2.3:a:microsoft:z3:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.