PoC Index

CVE-2020-13656

CRITICAL 9.8EPSS 2.1%

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
2.14% chance of exploitation in the next 30 days, 81th percentile
Published
2020-06-12
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related