CVE-2020-8315

Description

In Python (CPython) 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1, an insecure dependency load upon launch on Windows 7 may result in an attackers copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the systems copy. Windows 8 and later are unaffected.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.322

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Python 3.8.1Windows
Vulnerabilities CVE-2020-8315,CVE-2020-8492,CVE-2022-48564 are affected in Python 3.7.6Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.1.7Windows
Multiple Vulnerabilities are affected in IBM Cognos Analytics 11.2.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234