CVE-2020-8896 describes a buffer overflow vulnerability in the khcrypt implementation of Google Earth Pro versions up to and including 7.3.2. An attacker could exploit this by performing a Man-in-the-Middle attack with a specially crafted key, allowing them to read data beyond the intended buffer. This vulnerability is rated Medium severity (CVSS 5.9), with a network attack vector and high attack complexity, potentially leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Users are advised to update to Google Earth Pro 7.3.3 for mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.3.3CPE matchmatch criteria | cpe:2.3:a:google:earth:*:*:*:*:pro:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.