nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37001 CVE-2020-37001
HIGH
Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)
Record summary
CVE-2020-37001 has a selected CVSS score of 8.4 (high); EIP currently links 1 catalogued exploit.
Description
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 29, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Frigate ProfessionalBrowse Frigate3 / Frigate Professional | CVE List | 3.36.0.9 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFrigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)ExploitDB exploitby MasterVladNot analyzed1 file
References
4Archived Vendor Homepageproduct
https://web.archive.org/web/20171116000613/http://www.frigate3.com/index.php ExploitDB-48688exploit
https://www.exploit-db.com/exploits/48688 VulnCheck Advisory: Frigate Professional 3.36.0.9 - 'Pack File' Buffer Overflow (SEH Egghunter)Third-party advisory
https://www.vulncheck.com/advisories/frigate-professional-pack-file-buffer-overflow-seh-egghunter