CVE-2020-37031
Severity CVSS v4.0:
HIGH
Type:
CWE-787
Out-of-bounds Write
Publication date:
30/01/2026
Last modified:
30/01/2026
Description
Simple Startup Manager 1.17 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting memory through the 'File' input parameter. Attackers can craft a malicious payload with 268 bytes to trigger code execution, bypassing DEP and overwriting memory addresses to launch calc.exe.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.40
Severity 3.x
HIGH



