CVE-2020-9681 is an Uncontrolled Search Path vulnerability affecting Adobe Genuine Service version 6.6 and earlier, impacting Adobe, Apple, and Microsoft operating systems running the service. An authenticated attacker could exploit this with user interaction to rewrite administrator files, potentially leading to elevated permissions. This vulnerability has a CVSS score of 6.5 (Medium) due to its local attack vector and high impact on confidentiality, integrity, and availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is available and it's not on the KEV catalog, there has been limited community discussion and media coverage, indicating some awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.6CPE matchmatch criteria | cpe:2.3:a:adobe:genuine_service:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.