CVE-2016-20037

HIGH

xwpe 1.5.30a-2.1 Stack-based Buffer Overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20037. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in xwpe v1.5.30a-2.1 by supplying a maliciously crafted argument to the xwpe binary, leading to arbitrary code execution (RCE) via shellcode injection. The PoC includes a clear payload structure (junk, shellcode, NOPs, and EIP overwrite) and has been tested on Kali Linux 2.0.

Description

xwpe 1.5.30a-2.1 and prior contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying overly long input strings that exceed buffer boundaries. Attackers can craft malicious command-line arguments with 262 bytes of junk data followed by shellcode to overwrite the instruction pointer and achieve code execution or denial of service.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythonlocallinux
https://www.exploit-db.com/exploits/39285

This exploit demonstrates a stack-based buffer overflow in xwpe v1.5.30a-2.1 by supplying a maliciously crafted argument to the xwpe binary, leading to arbitrary code execution (RCE) via shellcode injection. The PoC includes a clear payload structure (junk, shellcode, NOPs, and EIP overwrite) and has been tested on Kali Linux 2.0.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: xwpe v1.5.30a-2.1
No auth needed
Prerequisites: xwpe installed on the target system · ability to execute the xwpe binary with malicious arguments
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-39285
https://www.exploit-db.com/exploits/39285
Product product
Official Product Homepage
http://www.identicalsoftware.com/xwpe
Third Party Advisory third-party-advisory
VulnCheck Advisory: xwpe 1.5.30a-2.1 Stack-based Buffer Overflow
https://www.vulncheck.com/advisories/xwpe-30a-stack-based-buffer-overflow

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 4.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
Identicalsoftware/xWPE 1.5.30a-2.1
Published Mar 28, 2026
Tracked Since Mar 29, 2026