7.8
CVSSv3

CVE-2018-20343

Published: 02/03/2020 Updated: 04/03/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a special map file to execute arbitrary code when the map file is loaded.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

advsys build engine 1.0

Github Repositories

PoC for CVE-2018-20343

CVE-2018-20343 This is a PoC for CVE-2018-20343, a vulnerability in Ken Silverman's Build Engine The generated map file triggers a buffer overflow and overwrites the stack as shown below: Open Watcom under DosBox 074-2: the analyst controls the stack Under FreeDos 12: the analyst controls EIP The vulnerable code is in ENGINEC: 1935 kread(fil,&am