CVE-2020-15523: High severity python 2.7 vulnerability
In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after PySetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this Python vulnerability?
The vulnerability ID is CVE-2020-15523.
What is the severity of CVE-2020-15523?
The severity of CVE-2020-15523 is high with a CVSS score of 7.8.
Which versions of Python are affected by CVE-2020-15523?
Python versions 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows are affected.
How can CVE-2020-15523 be exploited?
CVE-2020-15523 can be exploited by using a Trojan horse python3.dll in cases where CPython is embedded in a native application.
Are there any fixes or patches available for CVE-2020-15523?
Yes, patches and fixes for CVE-2020-15523 are available. Please refer to the references for more information.