CVE-2017-20226

HIGH

Mapscrn 2.0.3 Stack-Based Buffer Overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20226. PoCs published by Juan Sacco.

AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in Mapscrn (part of setfont) 2.0.3, leveraging a crafted buffer with NOP sleds and shellcode to achieve arbitrary code execution. The vulnerability arises from unsafe use of strcpy, leading to memory corruption and potential RCE.

Description

Mapscrn 2.0.3 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized input buffer. Attackers can craft a malicious buffer with junk data, return address, NOP instructions, and shellcode to overflow the stack and achieve code execution or denial of service.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythondoslinux
https://www.exploit-db.com/exploits/42144

This exploit demonstrates a stack-based buffer overflow in Mapscrn (part of setfont) 2.0.3, leveraging a crafted buffer with NOP sleds and shellcode to achieve arbitrary code execution. The vulnerability arises from unsafe use of strcpy, leading to memory corruption and potential RCE.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mapscrn (setfont) 2.0.3
No auth needed
Prerequisites: Mapscrn binary installed on target system · ability to execute the binary with malicious input
devstral-2 · analyzed Apr 08, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-42144
https://www.exploit-db.com/exploits/42144
Product product
Official Product Homepage
http://ccross.msk.su
Third Party Advisory third-party-advisory
VulnCheck Advisory: Mapscrn 2.0.3 Stack-Based Buffer Overflow
https://www.vulncheck.com/advisories/mapscrn-stack-based-buffer-overflow

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 4.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (1)
msk/Mapscrn 2.03
Published Mar 28, 2026
Tracked Since Mar 29, 2026