CVE-2020-37128
EmTec ZOC Terminal vulnerability analysis and mitigation

Overview

CVE-2020-37128 is a script processing vulnerability in ZOC Terminal version 7.25.5 that allows local attackers to crash the application by loading a maliciously crafted REXX script file. An attacker can generate an oversized script containing approximately 20,000 repeated characters to trigger an application crash, resulting in a denial of service. The vulnerability was formally published on February 5, 2026, and is classified as CWE-121 (Stack-based Buffer Overflow). It carries a CVSS v3.1 base score of 6.2 (Medium) and a CVSS v4.0 base score of 6.7 (Medium) (VulnCheck Advisory, Exploit-DB).

Technical details

The root cause is classified as CWE-121 (Stack-based Buffer Overflow), with an estimated secondary classification of CWE-400 (Uncontrolled Resource Consumption), indicating that the application fails to properly validate or limit the size of REXX script input before processing it. When ZOC Terminal 7.25.5 loads a REXX script file containing an oversized payload (approximately 20,000 repeated characters), the lack of bounds checking causes a stack-based buffer overflow that crashes the application. The attack vector is local, requiring no privileges and no user interaction beyond loading the malicious file. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).

Impact

Successful exploitation results in a denial of service — specifically, a crash of the ZOC Terminal application — with no impact on confidentiality or integrity. The scope is limited to the local system and the affected application, with no evidence of lateral movement potential or data exposure risk. Users relying on ZOC Terminal for SSH, Telnet, or serial communication sessions would lose connectivity during the crash (VulnCheck Advisory).

Exploitability

A public proof-of-concept exploit has been available on Exploit-DB (EDB-ID 48302) since the original discovery period, making this vulnerability straightforward to reproduce (Exploit-DB). The EPSS score is approximately 0.015% (0.000150), indicating a very low probability of active exploitation in the wild. There is no evidence of in-the-wild exploitation, threat actor attribution, or inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog (VulnCheck Advisory).

Exploitation steps

  1. Craft malicious REXX script: Create a REXX script file containing an oversized payload — for example, a string of approximately 20,000 repeated characters (e.g., A × 20000) within a valid REXX script structure.
  2. Deliver the file: Place the malicious .rexx or script file in a location accessible to the target user (e.g., shared folder, social engineering via email attachment, or direct file system access).
  3. Trigger loading: Convince the target user (or directly, if local access is available) to open or execute the malicious script file within ZOC Terminal 7.25.5 via the application's script loading functionality.
  4. Achieve denial of service: The application attempts to process the oversized input, triggering a stack-based buffer overflow that causes ZOC Terminal to crash, disrupting any active terminal sessions (Exploit-DB).

Indicators of compromise

  • File System: Presence of unusually large REXX script files (e.g., files containing thousands of repeated characters) in ZOC Terminal script directories or user-accessible locations.
  • Logs: Application crash logs or Windows Event Viewer entries referencing ZOC Terminal process termination (e.g., zoc.exe crash events with faulting module details).
  • Process: Unexpected termination of the zoc.exe process shortly after loading a script file.

Mitigation and workarounds

No official vendor patch has been confirmed for ZOC Terminal 7.25.5 in relation to this CVE. Users should avoid loading REXX script files from untrusted sources and restrict access to ZOC Terminal's script loading functionality where possible. Upgrading to the latest available version of ZOC Terminal from EmTec is recommended, as newer releases may address this issue (EmTec, VulnCheck Advisory).

Additional resources


SourceThis report was generated using AI

Related EmTec ZOC Terminal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-40147CRITICAL9.8
  • Homebrew logoHomebrew
  • zoc
NoYesAug 26, 2021
CVE-2021-32198CRITICAL9.8
  • Homebrew logoHomebrew
  • zoc
NoYesJun 06, 2021
CVE-2019-25589MEDIUM6.9
  • Homebrew logoHomebrew
  • cpe:2.3:a:emtec:zoc
NoNoMar 22, 2026
CVE-2020-37136MEDIUM6.7
  • EmTec ZOC Terminal logoEmTec ZOC Terminal
  • cpe:2.3:a:emtec:zoc
NoNoFeb 05, 2026
CVE-2020-37128MEDIUM6.7
  • EmTec ZOC Terminal logoEmTec ZOC Terminal
  • cpe:2.3:a:emtec:zoc
NoNoFeb 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management