CVE-2020-9563 is a heap overflow vulnerability affecting Adobe Bridge versions 10.0.1 and earlier, which could lead to arbitrary code execution. This high-severity vulnerability (CVSS 7.8) requires user interaction (UI:R) and local access (AV:L) for successful exploitation, but could result in high impact to confidentiality, integrity, and availability. While it has a relatively high FAUCET Risk Score of 74/100 and some media coverage, there is no evidence of active exploitation, no known exploit code in Metasploit or ExploitDB, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:bridge:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.