Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-37031. PoCs published by PovlTekstTV.
AI-analyzed exploit summary This exploit demonstrates a local buffer overflow in Simple Startup Manager 1.17, leveraging a JMP EBX and JMP EDI gadget from SETUPAPI.dll to execute a calc.exe payload. The PoC generates an exploit.txt file that triggers the vulnerability when pasted into the 'File' parameter.
Description
Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory through the 'File' input parameter. Attackers can craft a malicious payload with 268 bytes to trigger code execution, bypassing DEP and overwriting memory addresses to launch calc.exe.
Exploits (1)
This exploit demonstrates a local buffer overflow in Simple Startup Manager 1.17, leveraging a JMP EBX and JMP EDI gadget from SETUPAPI.dll to execute a calc.exe payload. The PoC generates an exploit.txt file that triggers the vulnerability when pasted into the 'File' parameter.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H