CVE-2016-20039

HIGH

Multi Emulator Super System 0.154-3.1 Buffer Overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-20039. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in MESS emulator 0.154-3.1 by overflowing the -gamma argument with a crafted payload containing shellcode, leading to arbitrary code execution. The PoC includes a functional exploit with a clear technical breakdown of the crash and register state.

Description

Multi Emulator Super System 0.154-3.1 contains a buffer overflow vulnerability in the gamma parameter handling that allows local attackers to crash the application or execute arbitrary code. Attackers can supply an oversized gamma parameter value to overflow the stack buffer and overwrite the instruction pointer with a controlled address to achieve code execution.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythonlocallinux
https://www.exploit-db.com/exploits/39673

This exploit demonstrates a buffer overflow vulnerability in MESS emulator 0.154-3.1 by overflowing the -gamma argument with a crafted payload containing shellcode, leading to arbitrary code execution. The PoC includes a functional exploit with a clear technical breakdown of the crash and register state.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Multi Emulator Super System (MESS) 0.154-3.1
No auth needed
Prerequisites: MESS emulator installed locally · Python environment to run the exploit
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-39673
https://www.exploit-db.com/exploits/39673
Product product
Official Product Homepage
http://mamedev.org/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Multi Emulator Super System 0.154-3.1 Buffer Overflow
https://www.vulncheck.com/advisories/multi-emulator-super-system-buffer-overflow

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
mamedev/Mess Emulator 0.154-3.1
Published Mar 28, 2026
Tracked Since Mar 29, 2026