CVE-2020-37142
10-Strike Network Inventory Explorer vulnerability analysis and mitigation

Overview

CVE-2020-37142 is a stack-based buffer overflow vulnerability in 10-Strike Network Inventory Explorer version 8.54 that allows local attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) records. The vulnerability was formally published on February 5, 2026, and was assigned by VulnCheck. It carries a CVSS v3.1 base score of 8.4 (High) and a CVSS v4.0 base score of 8.4 (High) (Feedly, VulnCheck).

Technical details

The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and resides in the application's handling of the 'Computer' parameter within the 'Add' function. An attacker can craft a malicious oversized input for this parameter, causing a buffer overflow that overwrites SEH records on the stack, ultimately redirecting execution flow to attacker-controlled code. The attack vector is local, requires no privileges, but does require user interaction (the user must invoke the 'Add' function with the malicious payload). A proof-of-concept exploit was previously published on Exploit-DB and a technical write-up was documented by researcher whitecr0wz (Exploit-DB, Web Archive).

Impact

Successful exploitation allows an attacker with local access to execute arbitrary code with the same privileges as the user running 10-Strike Network Inventory Explorer 8.54. This can result in full compromise of the affected system, including unauthorized access to sensitive inventory data, modification or deletion of system files, and disruption of application availability. The scope is limited to the local system, with no direct lateral movement capability, though post-exploitation access could facilitate further attacks within the network environment (Feedly, VulnCheck).

Exploitability

A proof-of-concept exploit for this vulnerability is publicly available on Exploit-DB (exploit #48253), and a detailed technical write-up was published by researcher whitecr0wz (Exploit-DB, Web Archive). Despite the public PoC, there is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.062%, indicating a low probability of exploitation in the near term. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify systems running 10-Strike Network Inventory Explorer version 8.54 with local or physical access.
  2. Prepare malicious payload: Craft an oversized string input designed to overflow the stack buffer associated with the 'Computer' parameter, including a SEH overwrite chain (nSEH jump + SEH handler pointer to attacker shellcode).
  3. Trigger the vulnerable function: Open the application and navigate to the 'Add' function (used to add a computer to the inventory). Input the crafted malicious payload into the 'Computer' parameter field.
  4. Overwrite SEH records: The oversized input overflows the stack buffer, overwriting the Structured Exception Handler records with attacker-controlled addresses.
  5. Achieve code execution: When the application triggers an exception (due to the overflow), the corrupted SEH chain redirects execution to the attacker's shellcode, resulting in arbitrary code execution with the privileges of the running application (Exploit-DB, Web Archive).

Indicators of compromise

  • Process: Unexpected child processes spawned by the 10-Strike Network Inventory Explorer process (e.g., cmd.exe, powershell.exe, or network tools) following use of the 'Add' function.
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) indicating unhandled exceptions in the Network Inventory Explorer process around the time the 'Add' function was used.
  • File System: Presence of unexpected executables, scripts, or payloads written to disk by the application process; new scheduled tasks or registry run keys created post-exploitation.
  • Network: Unusual outbound network connections originating from the Network Inventory Explorer process to external or unexpected internal IP addresses (Feedly, Exploit-DB).

Mitigation and workarounds

No official patch from 10-Strike Software has been confirmed for this vulnerability. Organizations should restrict local access to systems running 10-Strike Network Inventory Explorer 8.54 to trusted users only, and apply the principle of least privilege for application execution. Monitoring for suspicious activity related to the 'Add' function with unusual or oversized parameter inputs is recommended. Organizations should contact 10-Strike Software directly for security updates and consider evaluating alternative network inventory solutions if a patch remains unavailable (VulnCheck, Feedly).

Community reactions

The vulnerability received limited public attention, with automated alerts published by RedPacket Security and a mention in a CISA vulnerability bulletin for the week of February 2, 2026. No significant vendor statements or notable researcher commentary beyond the original whitecr0wz write-up have been identified (RedPacket Security, CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related 10-Strike Network Inventory Explorer vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2018-25344HIGH8.6
  • 10-Strike Network Inventory Explorer logo10-Strike Network Inventory Explorer
  • cpe:2.3:a:10-strike:network_inventory_explorer
NoYesMay 23, 2026
CVE-2020-37142HIGH8.4
  • 10-Strike Network Inventory Explorer logo10-Strike Network Inventory Explorer
  • cpe:2.3:a:10-strike:network_inventory_explorer
NoNoFeb 05, 2026
CVE-2020-37138HIGH8.4
  • 10-Strike Network Inventory Explorer logo10-Strike Network Inventory Explorer
  • cpe:2.3:a:10-strike:network_inventory_explorer
NoYesFeb 05, 2026
CVE-2020-36961HIGH8.4
  • 10-Strike Network Inventory Explorer logo10-Strike Network Inventory Explorer
  • cpe:2.3:a:10-strike:network_inventory_explorer
NoNoJan 28, 2026
CVE-2021-47772HIGH8.4
  • 10-Strike Network Inventory Explorer logo10-Strike Network Inventory Explorer
  • cpe:2.3:a:10-strike:network_inventory_explorer
NoNoJan 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management