Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
CISA KEV·Added 2021-11-03 — agencies required to remediate by 2021-11-17
.NET NuGet

GHSA-pv36-h7jh-qm62

MEDIUM

Heap buffer overflow in CefSharp

Also known asA-171232105ASB-A-171232105CVE-2020-15999
Published
Oct 27, 2020
Updated
Feb 3, 2025
Affected
4 pkgs
Patched
4 / 4
Exploits
7 known

EPSS Exploitation Probability

via FIRST.org ↗
93.0%probability of exploitation in next 30 days
Very High Risk100th percentile0.00%
92.4%92.8%93.2%93.5%93.0%93.0%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Blast Radius

4 pkgs affected
.NETCefSharp.Common.NETCefSharp.Wpf.NETCefSharp.WinForms.NETCefSharp.Wpf.HwndHost

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects NuGet packages — download data is not available via public APIs for these ecosystems.

Description

Impact

A memory corruption bug(Heap overflow) in the FreeType font rendering library.

This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .

As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/

Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.

Patches

Upgrade to 85.3.130 or higher

References

To review the CEF/Chromium patch see https://bitbucket.org/chromiumembedded/cef/commits/cd6cbe008b127990036945fb75e7c2c1594ab10d

Affected Packages

4 total 4 fixed
EcosystemPackageVulnerable rangeFix
.NETNuGetCefSharp.Commonall versions85.3.130
.NETNuGetCefSharp.Wpfall versions85.3.130
.NETNuGetCefSharp.WinFormsall versions85.3.130
.NETNuGetCefSharp.Wpf.HwndHostall versions85.3.130
Exploits & PoCs
7

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

Frequently Asked Questions

### Impact A memory corruption bug(Heap overflow) in the FreeType font rendering library. > This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images . As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild. ### Patches Upgrade to 85.3.130 or higher ### References - https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/ - https://www.zdnet.com/article/google-releases-chrome-security-update-
O3 Security · Impact-Aware SCA

Is GHSA-pv36-h7jh-qm62 in your stack?

O3 detects GHSA-pv36-h7jh-qm62 across NuGet dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.