First published: Tue Jan 28 2020(Updated: )
In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. Windows 8 and later are unaffected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Python Python | >=3.6.0<=3.6.10 | |
Python Python | >=3.7.0<=3.7.6 | |
Python Python | >=3.8.0<=3.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this security issue in Python is CVE-2020-8315.
CVE-2020-8315 has a severity rating of 9.8, which is considered critical.
Python versions 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 are affected by CVE-2020-8315.
CVE-2020-8315 allows a remote attacker to execute arbitrary code on the system.
To fix CVE-2020-8315, it is recommended to update to a patched version of Python.