CVE-2020-37140
MEDIUMEverest 5.50.2100 - Denial of Service via File Open Dialog Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37140. PoCs published by Ivan Marmolejo.
AI-analyzed exploit summary This exploit generates a buffer overflow by creating a file with 450 'A' characters, which when loaded into Everest Ultimate Edition via the 'Open File' feature, causes a denial of service crash. The PoC is straightforward and relies on user interaction to trigger the vulnerability.
Description
Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.
Exploits (1)
This exploit generates a buffer overflow by creating a file with 450 'A' characters, which when loaded into Everest Ultimate Edition via the 'Open File' feature, causes a denial of service crash. The PoC is straightforward and relies on user interaction to trigger the vulnerability.
References (3)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H