CVE-2020-7384: Client-Side Command Injection in Rapid7 Metasploit
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this security vulnerability?
The vulnerability ID is CVE-2020-7384.
What is the severity rating of CVE-2020-7384?
The severity rating of CVE-2020-7384 is critical.
What is the affected software for CVE-2020-7384?
The affected software for CVE-2020-7384 is Rapid7 Metasploit version up to 4.19.0.
How can a malicious user exploit CVE-2020-7384?
A malicious user can exploit CVE-2020-7384 by crafting and publishing a malicious APK file that executes arbitrary commands on a victim's machine.
Where can I find more information about CVE-2020-7384?
You can find more information about CVE-2020-7384 at the following references: [Packet Storm Security Advisory](http://packetstormsecurity.com/files/160004/Rapid7-Metasploit-Framework-msfvenom-APK-Template-Command-Injection.html), [Packet Storm Security Advisory](http://packetstormsecurity.com/files/161200/Metasploit-Framework-6.0.11-Command-Injection.html), [GitHub Pull Request](https://github.com/rapid7/metasploit-framework/pull/14288).