QID 983240
QID 983240: Dotnet (nuget) Security Update for CefSharp.Wpf.HwndHost (GHSA-m7mf-48hp-5qmr)
CVE-2020-16009: Inappropriate implementation in V8
- https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-16009
Google is aware of reports that exploits for CVE-2020-16009 exist in the wild.
Allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
There is currently little to no public information on the issue other than it has been flagged as `High` severity.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-m7mf-48hp-5qmr for updates pertaining to this vulnerability.
Vendor References
- GHSA-m7mf-48hp-5qmr -
github.com/advisories/GHSA-m7mf-48hp-5qmr
CVEs related to QID 983240
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-m7mf-48hp-5qmr | CefSharp.Common |
|
|
| GHSA-m7mf-48hp-5qmr | CefSharp.WinForms |
|
|
| GHSA-m7mf-48hp-5qmr | CefSharp.Wpf |
|
|
| GHSA-m7mf-48hp-5qmr | CefSharp.Wpf.HwndHost |
|