CVE-2020-37234
MEDIUMInternet Download Manager 6.38.12 Scheduler Buffer Overflow
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2020-37234. PoCs published by Vincent Wolterman.
AI-analyzed exploit summary This Perl script generates a malformed text file containing a buffer overflow payload (1302 'A's, 2 'B's, and remaining 'C's) to trigger a crash in Internet Download Manager's Scheduler feature. The exploit targets a stack-based overflow in the 'Open the following file when done' input field, demonstrating a DoS condition.
Description
Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' field to trigger a denial of service condition.
Exploits (1)
This Perl script generates a malformed text file containing a buffer overflow payload (1302 'A's, 2 'B's, and remaining 'C's) to trigger a crash in Internet Download Manager's Scheduler feature. The exploit targets a stack-based overflow in the 'Open the following file when done' input field, demonstrating a DoS condition.
References (4)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H