PT-2020-20082 · Python+2 · Python+3

Anthony Wee

+1

·

Published

2020-01-28

·

Updated

2025-08-11

·

CVE-2020-8315

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Python (CPython) versions 3.6 through 3.6.10 Python (CPython) versions 3.7 through 3.7.6 Python (CPython) versions 3.8 through 3.8.1
Description An insecure dependency load upon launch on Windows 7 may result in an attacker's copy of api-ms-win-core-path-l1-1-0.dll being loaded and used instead of the system's copy. This issue does not affect Windows 8 and later.
Recommendations For versions 3.6 through 3.6.10, consider updating to a version outside of this range to mitigate the risk. For versions 3.7 through 3.7.6, consider updating to a version outside of this range to mitigate the risk. For versions 3.8 through 3.8.1, consider updating to a version outside of this range to mitigate the risk. As a temporary workaround, consider restricting the use of the api-ms-win-core-path-l1-1-0.dll library on Windows 7 systems until a patch is available.

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1597
ALT-PU-2021-2653
ALT-PU-2024-3474
BIT-LIBPYTHON-2020-8315
BIT-PYTHON-2020-8315
BIT-PYTHON-MIN-2020-8315
CVE-2020-8315
PSF-2020-7

Affected Products

Alt Linux
Python
Windows 7
Windows 8