Maple <= v13 Maplet File Creation and Command Execution
Vulnerability Description
Maple versions up to and including 13's Maplet framework allows embedded commands to be executed automatically when a .maplet file is opened. This behavior bypasses standard security restrictions that normally prevent code execution in regular Maple worksheets. The vulnerability enables attackers to craft malicious .maplet files that execute arbitrary code without user interaction.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-20120
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- scriptjunkie
References
- https://www.maplesoft.com/products/maple/
- https://www.exploit-db.com/exploits/16308
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/fileformat/maple_maplet.rb
- https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:MISC:MAPLE-MAPLET-CMD-EXEC.html
- https://www.vulncheck.com/advisories/maple-maplet-file-creation-command-execution
Affected Vendor
Maplesoft
View all reports →