← Vulnerability feed

Vulnerability record · CVE-2020-14049 · published 22 June 2020

CVE-2020-14049: Rakuten viber argument injection vulnerability

Rakuten · Viber

Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password cracking. NOTE: this issue exists because of an incomplete fix for CVE-2019-12569.

7.5 CVSS 3.1 High EPSS 2.2% · top 18.5% CWE-88 · Argument injection
7.5CVSS 3.1 base score, v2 5.0
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Viber for Windows up to 13.2.0.39 does not properly quote its custom URI handler. A malicious website could launch Viber with arbitrary parameters, forcing a victim to send an NTLM authentication request, and either relay the request or capture the hash for offline password cracking. NOTE: this issue exists because of an incomplete fix for CVE-2019-12569.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://jeffs.sh/CVEs/CVE-2020-14049.txt ExploitMitigationThird Party Advisory
https://www.viber.com/en/security/ Vendor Advisory
https://jeffs.sh/CVEs/CVE-2020-14049.txt ExploitMitigationThird Party Advisory
https://www.viber.com/en/security/ Vendor Advisory

Track CVE-2020-14049 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-13476Rakuten viber broken cryptographic algorithm vulnerabilityRakuten Viber Cloak mode in Android v25.7.2.0g and Windows v25.6.0.0–v25.8.1.0 uses a static and predictable TLS ClientHello fingerprint lacking exte…EPSS 0.35%8.8CVE-2019-18800Rakuten viber missing encryption vulnerabilityViber through 11.7.0.5 allows a remote attacker who can capture a victim's internet traffic to steal their Viber account, because not all Viber proto…EPSS 1.7%7.8CVE-2019-12569Rakuten viber untrusted search path vulnerabilityA vulnerability in Viber before 10.7.0 for Desktop (Windows) could allow an attacker to execute arbitrary commands on a targeted system. This vulnera…EPSS 15%6.3CVE-2025-55996Rakuten viber cross-site scripting vulnerabilityViber Desktop 25.6.0 is vulnerable to HTML Injection via the text parameter of the message compose/forward interfaceEPSS 0.19%5.5CVE-2018-3987Rakuten viber information exposure vulnerabilityAn exploitable information disclosure vulnerability exists in the 'Secret Chats' functionality of Rakuten Viber on Android 9.3.0.6. The 'Secret Chats…EPSS 0.38%9.2CVE-2026-86060MikroTik RouterOS SSH login argument injection privilege escalationRouterOS mishandles arguments in the SSH login path when a username begins with a prohibited character, allowing the trusted policy mask to be altere…KEVEPSS 1.8%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2020-14049), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.