CVE-2020-7384

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
29/10/2020
Last modified:
03/02/2021

Description

Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:* 4.19.0 (excluding)