CVE-2014-2206

GetGo Download Manager <4.9.0.1982 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-2206. PoCs published by Julien Ahrens, Julien Ahrens, Gabor Seljan, bzyo, sinn3r, including Metasploit module exploits/windows/browser/getgodm_http_response_bof.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in GetGo Download Manager v4.9.0.1982 via a maliciously crafted HTTP response header. It leverages SEH overwrite and SafeSEH bypass to execute arbitrary shellcode (calc.exe payload).

Description

Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Julien Ahrens · pythonremotewindows
https://www.exploit-db.com/exploits/32132

This exploit targets a buffer overflow vulnerability in GetGo Download Manager v4.9.0.1982 via a maliciously crafted HTTP response header. It leverages SEH overwrite and SafeSEH bypass to execute arbitrary shellcode (calc.exe payload).

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GetGo Download Manager v4.9.0.1982
No auth needed
Prerequisites: Network access to the target · Target running GetGo Download Manager v4.9.0.1982
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by Julien Ahrens, Gabor Seljan, bzyo, sinn3r · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/getgodm_http_response_bof.rb

This Metasploit module exploits a stack-based buffer overflow in GetGo Download Manager via an overly long HTTP response header. It includes two exploit methods for versions 4.9.0.1982 and 5.3.0.2712, leveraging SEH overwrites and structured payload delivery.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GetGo Download Manager 4.9.0.1982 and 5.3.0.2712
No auth needed
Prerequisites: Victim must be tricked into downloading a file from a malicious server
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (3)

Core 3

Scores

EPSS 0.6144
EPSS Percentile 99.1%

Details

CWE
CWE-119
Status published
Products (3)
getgosoft/getgo_download_manager 4.8.2.1346
getgosoft/getgo_download_manager 4.9.0.1982
getgosoft/getgo_download_manager < 4.4.5.502
Published Mar 05, 2014
Tracked Since Feb 18, 2026