Vulnerability Description
Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially executing system commands like calc.exe.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://www.codeblocks.org/
- https://sourceforge.net/projects/codeblocks
- https://www.exploit-db.com/exploits/48594
- https://www.vulncheck.com/advisories/code-blocks-file-name-local-buffer-overflow
FAQ
What is CVE-2020-37040?
CVE-2020-37040 is a vulnerability with a CVSS score of 8.4 (HIGH). Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vu...
How severe is CVE-2020-37040?
CVE-2020-37040 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37040?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.