High severity7.0NVD Advisory· Published Oct 29, 2020· Updated Jun 17, 2026
CVE-2020-7384
CVE-2020-7384
Description
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:rapid7:metasploit:*:*:*:*:*:*:*:*range: <4.19.0
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
3- packetstormsecurity.com/files/160004/Rapid7-Metasploit-Framework-msfvenom-APK-Template-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- packetstormsecurity.com/files/161200/Metasploit-Framework-6.0.11-Command-Injection.htmlnvdExploitThird Party AdvisoryVDB Entry
- github.com/rapid7/metasploit-framework/pull/14288nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.