CVE-2020-3760: Command Injection
Published Feb 13, 2020
·Updated
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
Affected Software
4 affected components
Adobe Digital Editions<=4.5.10
Microsoft Windows
All of the following
Adobe Digital Editions<=4.5.10
Microsoft Windows
Event History
Feb 13, 2020
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-3760?
CVE-2020-3760 is a command injection vulnerability in Adobe Digital Editions versions 4.5.10 and below.
2
What is the severity of CVE-2020-3760?
CVE-2020-3760 has a severity rating of critical, with a CVSS score of 9.8.
3
How can CVE-2020-3760 be exploited?
CVE-2020-3760 can be exploited by injecting malicious commands, which could lead to arbitrary code execution.
4
Is Microsoft Windows affected by CVE-2020-3760?
No, Microsoft Windows is not affected by CVE-2020-3760.
5
How can I fix CVE-2020-3760?
To fix CVE-2020-3760, update Adobe Digital Editions to a version higher than 4.5.10.