CVE-2020-37221
HIGHAtomic Alarm Clock 6.3 Stack Overflow via SEH Unicode
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37221. PoCs published by boku.
AI-analyzed exploit summary This exploit demonstrates a stack-based buffer overflow in Atomic Alarm Clock 6.3 beta, leveraging Unicode and SEH overwrite to achieve arbitrary code execution. The payload includes a custom decoder and shellcode to launch calc.exe, bypassing bad characters and ASLR.
Description
Atomic Alarm Clock 6.3 contains a stack overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string to the display name textbox in the Time Zones Clock configuration. Attackers can craft a buffer with structured exception handling overwrite and encoded shellcode to bypass SafeSEH protections and execute arbitrary commands with application privileges.
Exploits (1)
This exploit demonstrates a stack-based buffer overflow in Atomic Alarm Clock 6.3 beta, leveraging Unicode and SEH overwrite to achieve arbitrary code execution. The payload includes a custom decoder and shellcode to launch calc.exe, bypassing bad characters and ASLR.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H