Vulnerability Description
Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Aida64 | Aida64 | 5.50.2100 |
Related Weaknesses (CWE)
References
- https://web.archive.org/web/20191223010612/https://www.aida64.com/Product
- https://www.exploit-db.com/exploits/48259ExploitThird Party AdvisoryVDB Entry
- https://www.vulncheck.com/advisories/everest-open-file-denial-of-serviceThird Party Advisory
FAQ
What is CVE-2020-37140?
CVE-2020-37140 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can g...
How severe is CVE-2020-37140?
CVE-2020-37140 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-37140?
Check the references section above for vendor advisories and patch information. Affected products include: Aida64 Aida64.