CVE-2020-25207: Critical severity jetbrains toolbox app vulnerability
Published Nov 16, 2020
·Updated
JetBrains ToolBox before version 1.18 is vulnerable to Remote Code Execution via a browser protocol handler.
Affected Software
2 affected componentsFixes available
JetBrains Toolbox<1.18
Microsoft cbl2 toolbox 0.0.18-9
Event History
Nov 16, 2020
CVE Published
via MITRE·03:01 PM
Data Sourced
via MITRE·03:01 PM
Description
Oct 1, 2025
Data Sourced
via Microsoft·11:11 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·11:11 PM
Affected Software
Updated
via Microsoft·11:11 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2020-25207?
CVE-2020-25207 is a vulnerability in JetBrains ToolBox before version 1.18 that allows for remote code execution via a browser protocol handler.
2
How severe is CVE-2020-25207?
CVE-2020-25207 has a severity rating of 9.8 (Critical).
3
Which version of JetBrains ToolBox is affected by CVE-2020-25207?
JetBrains ToolBox version 1.18 and earlier are affected by CVE-2020-25207.
4
How can I fix CVE-2020-25207?
Update JetBrains ToolBox to version 1.18 or newer to fix CVE-2020-25207.
5
Where can I find more information about CVE-2020-25207?
More information about CVE-2020-25207 can be found at the following references: [Reference 1](https://blog.jetbrains.com) and [Reference 2](https://blog.jetbrains.com/2020/11/16/jetbrains-security-bulletin-q3-2020/).