GHSA-xgww-h98f-24qf · Severity: high · Ecosystem: rubygems — Metasploit Framework user exposes Metasploit to same deserialization issue that is exploited by that module
By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework typically runs with elevated privileges, this can lead to a system compromise on the Metasploit workstation. Note that an attacker would have to lie in wait and entice the Metasploit user to run the affected module against a malicious endpoint in a "hack-back" type of attack. Metasploit is only vulnerable when the drb_remote_codeexec module is running. In most cases, this cannot happen automatically.
Conclusion & alert: CVE-2020-7385 is rated High Exploit Risk (70.8/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.58%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-30 | 0.45% | 0.58% | +0.13% |
| 2 | 2025-03-29 | 0.65% | 0.45% | -0.20% |
| 3 | 2025-01-08 | — | 0.65% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.1 | 3.1 | HIGH |
|
2.8 | 5.2 | [email protected] |
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-xgww-h98f-24qf · Severity: high · Ecosystem: rubygems — Metasploit Framework user exposes Metasploit to same deserialization issue that is exploited by that module
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| rapid7 | metasploit | < 4.19.0 | cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/rapid7/metasploit-framework/pull/14300 | Exploit Patch Third Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/14335 | Patch Third Party Advisory |
| https://help.rapid7.com/metasploit/release-notes/archive/2020/10/ | Release Notes Vendor Advisory |