CVE-2020-37136
EmTec ZOC Terminal vulnerability analysis and mitigation

Overview

CVE-2020-37136 is a stack-based buffer overflow (denial of service) vulnerability in ZOC Terminal version 7.25.5, affecting the private key file input field used during SSH key file creation. An attacker can overwrite the private key file input with a 2000-byte buffer, causing the application to crash and become unresponsive. The vulnerability was formally published on February 5, 2026, and is assigned a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 6.7 (Medium) (VulnCheck Advisory, Exploit-DB).

Technical details

The root cause is a stack-based buffer overflow (CWE-121) in ZOC Terminal's handling of the private key file input field. When a user attempts to create SSH key files, the application fails to properly validate the length of input supplied to the private key file field, allowing an oversized buffer (~2000 bytes) to overflow the stack and crash the process. The attack vector is local user interaction (the attacker must supply malicious input to the field), though the CVSS v3.1 vector rates it as network-accessible with no privileges required, reflecting the potential for a crafted file or remote scenario. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).

Impact

Successful exploitation results in a denial of service — the ZOC Terminal application crashes and becomes unresponsive, disrupting SSH session management and key file operations for the affected user. There is no known confidentiality or integrity impact; the vulnerability is limited to availability. The scope is confined to the local application instance, with no evidence of lateral movement potential or data exfiltration risk (VulnCheck Advisory).

Exploitability

A public proof-of-concept exploit has been available on Exploit-DB (EDB-ID 48292) since at least 2020, predating the formal CVE publication (Exploit-DB). The EPSS score is approximately 0.037%, indicating a low probability of active exploitation in the wild. There is no known threat actor attribution, no evidence of in-the-wild exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (VulnCheck Advisory).

Exploitation steps

  1. Identify target: Confirm the target system is running ZOC Terminal version 7.25.5 on Windows or macOS.
  2. Access SSH key creation dialog: Open ZOC Terminal and navigate to the SSH key file creation or configuration dialog that exposes the private key file input field.
  3. Supply oversized input: Enter or paste a buffer of approximately 2000 bytes (e.g., a string of 'A' characters) into the private key file input field.
  4. Trigger crash: Attempt to proceed with the SSH key file operation; the application will overflow the stack buffer and crash, rendering ZOC Terminal unresponsive (Exploit-DB).

Indicators of compromise

  • Process: ZOC Terminal process (zoc.exe or zoc) terminates unexpectedly or becomes unresponsive during SSH key file creation.
  • Logs: Application crash logs or Windows Event Viewer entries referencing ZOC Terminal process termination with an access violation or stack overflow error.
  • File System: Presence of crash dump files (e.g., .dmp files) generated by the OS in the user's temp directory or ZOC Terminal installation folder following the crash.

Mitigation and workarounds

No vendor patch or official advisory from EmTec has been identified for this specific vulnerability. Users should avoid entering untrusted or excessively long strings into the private key file input field in ZOC Terminal 7.25.5. Upgrading to the latest available version of ZOC Terminal from the vendor's website (https://www.emtec.com) is recommended, as newer versions may address this issue. Organizations should monitor the EmTec website for security updates (VulnCheck Advisory).

Additional resources


SourceThis report was generated using AI

Related EmTec ZOC Terminal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-40147CRITICAL9.8
  • Homebrew logoHomebrew
  • zoc
NoYesAug 26, 2021
CVE-2021-32198CRITICAL9.8
  • Homebrew logoHomebrew
  • zoc
NoYesJun 06, 2021
CVE-2019-25589MEDIUM6.9
  • Homebrew logoHomebrew
  • cpe:2.3:a:emtec:zoc
NoNoMar 22, 2026
CVE-2020-37136MEDIUM6.7
  • EmTec ZOC Terminal logoEmTec ZOC Terminal
  • cpe:2.3:a:emtec:zoc
NoNoFeb 05, 2026
CVE-2020-37128MEDIUM6.7
  • EmTec ZOC Terminal logoEmTec ZOC Terminal
  • cpe:2.3:a:emtec:zoc
NoNoFeb 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management