CVE-2020-37140
FinalWire AIDA64 vulnerability analysis and mitigation

Overview

CVE-2020-37140 is a denial of service (DoS) vulnerability in Everest (later rebranded as AIDA64) version 5.50.2100, developed by FinalWire. The flaw allows local attackers to crash the application by pasting a specially crafted 450-byte buffer of repeated characters into the file open dialog. It was formally published on February 5, 2026, and assigned by VulnCheck. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 4.6 (Medium) (Feedly, VulnCheck Advisory).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write), with an estimated secondary classification of CWE-125 (Out-of-bounds Read). The vulnerability is triggered when a local attacker pastes an oversized 450-byte buffer of repeated characters into the application's file open dialog, causing improper memory handling that results in an application crash. Exploitation requires local access and user interaction (opening the file dialog), but no elevated privileges are needed. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).

Impact

Successful exploitation results in a complete crash of the AIDA64/Everest application, disrupting its system monitoring and hardware diagnostics functionality. The impact is limited to availability — there is no confidentiality or integrity impact. Because the attack is local and confined to the application process, there is no risk of lateral movement or sensitive data exposure beyond the loss of the application's diagnostic capabilities (Feedly).

Exploitability

A proof-of-concept exploit is publicly available on Exploit-DB (EDB-48259), demonstrating the crash technique (Exploit-DB). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, reflecting a very low probability of exploitation in the near term (Feedly).

Exploitation steps

  1. Local Access: Obtain local access to a system running Everest or AIDA64 version 5.50.2100.
  2. Generate Payload: Create a 450-byte string of repeated characters (e.g., a string of 450 'A' characters) using a script or manually.
  3. Open File Dialog: Launch the AIDA64/Everest application and navigate to the file open functionality to trigger the file open dialog.
  4. Paste Payload: Paste the 450-byte buffer into the file open dialog's input field.
  5. Trigger Crash: Submit or interact with the dialog; the application will crash due to an out-of-bounds memory write, resulting in a denial of service (Exploit-DB).

Indicators of compromise

  • Process: Unexpected termination of the AIDA64 or Everest process (e.g., crash dump generated in the application directory or Windows Event Log showing application fault for aida64.exe).
  • Logs: Windows Application Event Log entries (Event ID 1000) indicating a faulting application for aida64.exe with an access violation or memory-related exception.
  • File System: Presence of crash dump files (.dmp) in the application directory or %LOCALAPPDATA%\CrashDumps associated with the AIDA64 process.

Mitigation and workarounds

No official vendor patch has been identified for this specific version. As interim mitigations, restrict local access to systems running AIDA64 5.50.2100 to trusted users only, and implement access controls to limit which users can interact with the application. Organizations should consider upgrading to a newer version of AIDA64 from FinalWire, as later releases may address this issue. Monitor for suspicious interactions with the application's file dialog as an additional precaution (VulnCheck Advisory).

Additional resources


SourceThis report was generated using AI

Related FinalWire AIDA64 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-25633HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25631HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25629HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25360HIGH8.4
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 18, 2026
CVE-2020-37140MEDIUM4.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management