CVE-2020-9650 is an out-of-bounds write vulnerability affecting Adobe Media Encoder versions 14.2 and earlier. Successful exploitation could lead to arbitrary code execution, posing a high risk to system integrity. With a CVSS score of 7.8 (HIGH), this vulnerability requires user interaction (UI:R) for exploitation, typically through a malicious file. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, the vulnerability has garnered some community discussion and media coverage, indicating awareness. It is not listed in CISA's KEV catalog, suggesting it is not under active, widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 14.2CPE matchmatch criteria | cpe:2.3:a:adobe:media_encoder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.