CVE-2017-20228

HIGH

Flat Assembler 1.71.21 Stack-Based Buffer Overflow ROP

Title source: cna
STIX 2.1

Description

Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return-oriented programming chains for shell command execution.

Exploits (1)

exploitdb WORKING POC
by Juan Sacco · pythonlocallinux
https://www.exploit-db.com/exploits/42265

Scores

CVSS v3 8.4
EPSS 0.0002
EPSS Percentile 6.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
Flatassembler/Flat Assembler 1.71.21
flatassembler/flat_assembler < 1.71.21
Published Mar 28, 2026
Tracked Since Mar 29, 2026