QID 982992
QID 982992: Dotnet (nuget) Security Update for CefSharp.Wpf.HwndHost (GHSA-x7fx-mcc9-27j7)
High CVE-2020-16013: Inappropriate implementation in V8.
- https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop_11.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16013
Google is aware of reports that exploits for CVE-2020-16013 and CVE-2020-16017 exist in the wild.
There is currently little to no public information on the issue other than it has been flagged as `High` severity.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-x7fx-mcc9-27j7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-x7fx-mcc9-27j7 -
github.com/advisories/GHSA-x7fx-mcc9-27j7
CVEs related to QID 982992
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-x7fx-mcc9-27j7 | CefSharp.Common |
|
|
| GHSA-x7fx-mcc9-27j7 | CefSharp.WinForms |
|
|
| GHSA-x7fx-mcc9-27j7 | CefSharp.Wpf |
|
|
| GHSA-x7fx-mcc9-27j7 | CefSharp.Wpf.HwndHost |
|