CVE-2020-13520
An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.11%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An out of bounds memory corruption vulnerability exists in the way Pixar OpenUSD 20.05 reconstructs paths from binary USD files. A specially crafted malformed file can trigger an out of bounds memory modification which can result in remote code execution. To trigger this vulnerability, victim needs to access an attacker-provided malformed file.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.11% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-787
- Affected
- pixar/openusd · apple/macos
- Source
- talos-cna@cisco.com
References
- https://support.apple.com/kb/HT212011Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1120Exploit, Technical Description, Third Party Advisory
- https://support.apple.com/kb/HT212011Third Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2020-1120Exploit, Technical Description, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.