
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-37140 is a denial of service (DoS) vulnerability in Everest (later rebranded as AIDA64) version 5.50.2100, developed by FinalWire. The flaw allows local attackers to crash the application by pasting a specially crafted 450-byte buffer of repeated characters into the file open dialog. It was formally published on February 5, 2026, and assigned by VulnCheck. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) and a CVSS v4.0 base score of 4.6 (Medium) (Feedly, VulnCheck Advisory).
The root cause is classified as CWE-787 (Out-of-bounds Write), with an estimated secondary classification of CWE-125 (Out-of-bounds Read). The vulnerability is triggered when a local attacker pastes an oversized 450-byte buffer of repeated characters into the application's file open dialog, causing improper memory handling that results in an application crash. Exploitation requires local access and user interaction (opening the file dialog), but no elevated privileges are needed. A public proof-of-concept exploit is available on Exploit-DB (Exploit-DB, VulnCheck Advisory).
Successful exploitation results in a complete crash of the AIDA64/Everest application, disrupting its system monitoring and hardware diagnostics functionality. The impact is limited to availability — there is no confidentiality or integrity impact. Because the attack is local and confined to the application process, there is no risk of lateral movement or sensitive data exposure beyond the loss of the application's diagnostic capabilities (Feedly).
A proof-of-concept exploit is publicly available on Exploit-DB (EDB-48259), demonstrating the crash technique (Exploit-DB). There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.017%, reflecting a very low probability of exploitation in the near term (Feedly).
aida64.exe).aida64.exe with an access violation or memory-related exception..dmp) in the application directory or %LOCALAPPDATA%\CrashDumps associated with the AIDA64 process.No official vendor patch has been identified for this specific version. As interim mitigations, restrict local access to systems running AIDA64 5.50.2100 to trusted users only, and implement access controls to limit which users can interact with the application. Organizations should consider upgrading to a newer version of AIDA64 from FinalWire, as later releases may address this issue. Monitor for suspicious interactions with the application's file dialog as an additional precaution (VulnCheck Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."