CVE-2017-20225

CRITICAL

TiEmu 2.08 Stack-Based Buffer Overflow Vulnerability

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20225. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in TiEmu 2.08 and prior, leveraging a SEH overwrite and ROP chain to execute arbitrary shellcode. The payload is designed to achieve remote code execution by bypassing DEP via VirtualProtect.

Description

TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can trigger the overflow through command-line arguments passed to the application, leveraging ROP gadgets to bypass protections and execute shellcode in the application context.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythonlocalwindows
https://www.exploit-db.com/exploits/42087

This exploit demonstrates a stack-based buffer overflow in TiEmu 2.08 and prior, leveraging a SEH overwrite and ROP chain to execute arbitrary shellcode. The payload is designed to achieve remote code execution by bypassing DEP via VirtualProtect.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TiEmu (Texas Instrument Emulator) 2.08 and prior
No auth needed
Prerequisites: TiEmu installed on Windows 7 32-bit · Path to TiEmu executable at 'C:/Program Files/TiEmu/bin/tiemu.exe'
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-42087
https://www.exploit-db.com/exploits/42087
Product product
Official Product Homepage
http://lpg.ticalc.org/prj_tiemu/
Third Party Advisory third-party-advisory
VulnCheck Advisory: TiEmu 2.08 Stack-Based Buffer Overflow Vulnerability
https://www.vulncheck.com/advisories/tiemu-stack-based-buffer-overflow-vulnerability

Scores

CVSS v3 9.8
EPSS 0.0080
EPSS Percentile 51.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
ticalc/tiemu < 2.0.8
ticalc/TiEmu 2.08
Published Mar 28, 2026
Tracked Since Mar 29, 2026