CVE-2020-9626 is an out-of-bounds read vulnerability in Adobe DNG Software Development Kit (SDK) versions 1.5 and earlier, affecting both Adobe and Microsoft implementations on Windows. This vulnerability has a low CVSS score of 3.3, indicating a low attack complexity and local access requirement, with the primary impact being information disclosure. While it has garnered some community discussion and media coverage, there is no evidence of active exploitation, nor are there publicly available exploit tools like Metasploit or Nuclei modules. The vulnerability is not listed in CISA's KEV catalog, and its EPSS and FAUCET scores suggest a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5CPE matchmatch criteria | cpe:2.3:a:adobe:digital_negative_software_development_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.