CVE-2020-9850
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 77%
from disclosure to weapon0 days
Published on NVDJun 9
metasploitMar 18
exploitation probability
77%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
2 products (9 components)
Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 6
no_fix_planned: Out of support scope
Fixed
3 products (70 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Enterprise Linux Server (v. 7 ELS) · Red Hat Enterprise Linux Server Optional (v. 7 ELS)
Not affected
3 products (1,148 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat CodeReady Linux Builder (v. 8) · Red Hat Enterprise Linux BaseOS (v. 8)
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 13.5 and iPadOS 13.5, tvOS 13.4.5, watchOS 6.2.5, Safari 13.1.1, iTunes 12.10.7 for Windows, iCloud for Windows 11.2, iCloud for Windows 7.19. A remote attacker may be able to cause arbitrary code execution.