« Volver al listado

CVE-2020-15523

Estado: ModificadaAlta (7.8)—

In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-15523",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.9,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.4,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-07-04T23:15:10.313",
  "references": [
    {
      "url": "https://bugs.python.org/issue29778",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/python/cpython/pull/21297",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210312-0004/",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://bugs.python.org/issue29778",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://github.com/python/cpython/pull/21297",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210312-0004/",
      "tags": [
        "Issue Tracking",
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-427"
        },
        {
          "lang": "en",
          "value": "CWE-908"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Python 3.6 through 3.6.10, 3.7 through 3.7.8, 3.8 through 3.8.4rc1, and 3.9 through 3.9.0b4 on Windows, a Trojan horse python3.dll might be used in cases where CPython is embedded in a native application. This occurs because python3X.dll may use an invalid search path for python3.dll loading (after Py_SetPath has been used). NOTE: this issue CANNOT occur when using python.exe from a standard (non-embedded) Python installation on Windows."
    },
    {
      "lang": "es",
      "value": "En Python versiones 3.6 hasta 3.6.10, 3.7 hasta 3.7.8, 3.8 hasta 3.8.4rc1 y 3.9 hasta 3.9.0b4 en Windows, se puede usar una python3.dll de tipo caballo de Troya en los casos en que CPython está incorporado en una aplicación nativa. Esto se produce porque python3X.dll puede usar una ruta de búsqueda no válida para cargar python3.dll (después de que haya sido usado Py_SetPath). NOTA: este problema NO PUEDE ocurrir cuando se usa python.exe desde una instalación estándar (no incorporada) de Python en Windows"
    }
  ],
  "lastModified": "2026-06-17T02:56:47.070",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "190C1D3B-648D-46B5-AB7E-8575DB03585B",
              "versionEndExcluding": "3.5.10",
              "versionStartIncluding": "3.5.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7EB6A6FC-6C82-4543-8DAA-96FF2BACDB5C",
              "versionEndExcluding": "3.6.12",
              "versionStartIncluding": "3.6.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "045171F0-A76D-4385-B2AE-51479B425C45",
              "versionEndExcluding": "3.7.9",
              "versionStartIncluding": "3.7.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E9409BD5-670F-4C69-A4D2-ACF9AD8F335B",
              "versionEndExcluding": "3.8.4",
              "versionStartIncluding": "3.8.0"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.8.4:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25F65784-2F53-467D-8E72-02F619F1D73F"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2E45B3B6-8458-4C88-99FC-C21D6987AA41"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D05F0EE6-213A-48AF-8217-502681E10421"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58906E55-8502-42DC-9203-AC6B337A7A85"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:alpha4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80D043C7-0760-4B00-A487-533E1CF86AC7"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:alpha5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "73519BF7-7F38-441D-AA72-574AD94E7E5E"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:alpha6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D498F6E9-511C-451C-A39E-8514774D9F46"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D803324B-B2E7-47FA-8E2C-E456B6940FEE"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F5113CE-A28F-4319-8395-FB96542D8FFD"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DCE9E749-8464-4753-86E6-CFE9FB834032"
            },
            {
              "criteria": "cpe:2.3:a:python:python:3.9.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "37D52E7C-0317-476B-B5EB-2A5FAD567144"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BDFB1169-41A0-4A86-8E4F-FDA9730B1E94"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}