CVE-2020-9683 is an out-of-bounds read vulnerability affecting Adobe Photoshop CC 2019 and Photoshop 2020, which could lead to arbitrary code execution. With a CVSS score of 8.8 (High), it can be exploited remotely with low complexity, requiring user interaction, and resulting in high impacts to confidentiality, integrity, and availability. While the vulnerability is not listed in CISA's KEV catalog and lacks public exploit code in Metasploit or ExploitDB, it has garnered significant community discussion and media coverage, indicating awareness of its potential. Its FAUCET Risk Score of 93/100 and EPSS score suggest a notable likelihood of exploitation despite the absence of known public exploits.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 21.2CPE matchmatch criteria | cpe:2.3:a:adobe:photoshop:*:*:*:*:*:*:*:* | ||
<= 20.0.9CPE matchmatch criteria | cpe:2.3:a:adobe:photoshop_cc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.