← back
CVE-2010-20120highCWE-94

Maple <= v13 Maplet File Creation and Command Execution

36Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.4epss 0.4%
from disclosure to weapon0 days
Published on NVDAug 21
metasploitApr 26
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This behavior bypasses standard security restrictions that normally prevent code execution in regular Maple worksheets. The vulnerability enables attackers to craft malicious .maplet files that execute arbitrary code without user interaction.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Maplesoft · Maple