CVE-2020-7745

HIGH

MintegralAdSDK < 6.6.0.0 - Remote Code Execution via Malicious Backdoor

Title source: llm
STIX 2.1

Description

This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitrary code on a user device.

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
https://snyk.io/blog/remote-code-execution-rce-sourmint/
Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-COCOAPODS-MINTEGRALADSDK-1019377
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=n-mEMkeoUqs

Scores

CVSS v3 7.1
EPSS 0.0255
EPSS Percentile 83.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N

Details

CWE
CWE-94
Status published
Products (1)
mintegral/mintegraladsdk < 6.6.0.0
Published Oct 19, 2020
Tracked Since Feb 18, 2026