CVE-2020-24972
HIGH 8.8EPSS 4.8%
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - CVSS v2.0
- 6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P - EPSS
- 4.76% chance of exploitation in the next 30 days, 91th percentile
- Published
- 2020-08-29
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- SpiralBL0CK/CVE-2020-249721★ · 2024-09-03