Inappropriate implementation in V8 in CefSharp

Description

High CVE-2020-16013: Inappropriate implementation in V8.

  • https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html
  • https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16013

Google is aware of reports that exploits for CVE-2020-16013 and CVE-2020-16017 exist in the wild.

There is currently little to no public information on the issue other than it has been flagged as High severity.

Basic information

Type
reviewed
Severity
high
Advisory on GitHub
Open advisory ↗
Repository advisory
Open repository advisory ↗
Source code
Not specified
Published (advisory)
2020-11-27 20:12:55 UTC
Updated
2023-02-01 05:05:09 UTC
GitHub reviewed
2020-11-27 20:12:35 UTC
NVD published
2021-01-08

EPSS Score

Score Percentile
26.14% 96.12%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer
CWE-787 Out-of-bounds Write

Affected packages (4)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
nuget CefSharp.Common < 86.0.241 86.0.241
nuget CefSharp.Wpf < 86.0.241 86.0.241
nuget CefSharp.WinForms < 86.0.241 86.0.241
nuget CefSharp.Wpf.HwndHost < 86.0.241 86.0.241

References

cvelogic Threat Intelligence