CVE-2020-37140

MEDIUM

Everest 5.50.2100 - Denial of Service via File Open Dialog Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-37140. PoCs published by Ivan Marmolejo.

AI-analyzed exploit summary This exploit generates a buffer overflow by creating a file with 450 'A' characters, which when loaded into Everest Ultimate Edition via the 'Open File' feature, causes a denial of service crash. The PoC is straightforward and relies on user interaction to trigger the vulnerability.

Description

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.

Exploits (1)

exploitdb WORKING POC
by Ivan Marmolejo · pythondoswindows
https://www.exploit-db.com/exploits/48259

This exploit generates a buffer overflow by creating a file with 450 'A' characters, which when loaded into Everest Ultimate Edition via the 'Open File' feature, causes a denial of service crash. The PoC is straightforward and relies on user interaction to trigger the vulnerability.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Everest Ultimate Edition 5.50.2100
No auth needed
Prerequisites: Local access to the target system · Everest Ultimate Edition installed · User interaction to open the malicious file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/48259

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 11.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
aida64/aida64 5.50.2100
FinalWire/Everest 5.50.2100
Published Feb 05, 2026
Tracked Since Feb 18, 2026