nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37031 CVE-2020-37031
HIGH
Simple Startup Manager 1.17 - 'File' Local Buffer Overflow
Record summary
CVE-2020-37031 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory through the 'File' input parameter. Attackers can craft a malicious payload with 268 bytes to trigger code execution, bypassing DEP and overwriting memory addresses to launch calc.exe.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 3, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Simple Startup ManagerBrowse Ashkon Software / Simple Startup Manager | CVE List | 1.17 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBSimple Startup Manager 1.17 - 'File' Local Buffer Overflow (PoC)ExploitDB exploitby PovlTekstTVNot analyzed1 file
References
4Product Webpageproduct
https://www.ashkon.com/startup_manager.html ExploitDB-48678exploit
https://www.exploit-db.com/exploits/48678 VulnCheck Advisory: Simple Startup Manager 1.17 - 'File' Local Buffer OverflowThird-party advisory
https://www.vulncheck.com/advisories/simple-startup-manager-file-local-buffer-overflow