CVE-2020-13656

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
12/06/2020
Last modified:
22/06/2020

Description

In Morgan Stanley Hobbes through 2020-05-21, the array implementation lacks bounds checking, allowing exploitation of an out-of-bounds (OOB) read/write vulnerability that leads to both local and remote code (via RPC) execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:morganstanley:hobbes:*:*:*:*:*:*:*:* 2020-05-21 (including)