CVE-2020-3725 is an out-of-bounds write vulnerability affecting Adobe Framemaker versions 2019.0.4 and earlier on Windows. This high-severity flaw, with a CVSS score of 8.8, can be exploited remotely with low complexity, requiring user interaction, and could lead to arbitrary code execution, compromising confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, its EPSS score indicates a higher-than-average likelihood of exploitation. The vulnerability has received limited community discussion and media coverage, with one article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019.0.4CPE matchmatch criteria | cpe:2.3:a:adobe:framemaker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.