
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-37142 is a stack-based buffer overflow vulnerability in 10-Strike Network Inventory Explorer version 8.54 that allows local attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) records. The vulnerability was formally published on February 5, 2026, and was assigned by VulnCheck. It carries a CVSS v3.1 base score of 8.4 (High) and a CVSS v4.0 base score of 8.4 (High) (Feedly, VulnCheck).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow) and resides in the application's handling of the 'Computer' parameter within the 'Add' function. An attacker can craft a malicious oversized input for this parameter, causing a buffer overflow that overwrites SEH records on the stack, ultimately redirecting execution flow to attacker-controlled code. The attack vector is local, requires no privileges, but does require user interaction (the user must invoke the 'Add' function with the malicious payload). A proof-of-concept exploit was previously published on Exploit-DB and a technical write-up was documented by researcher whitecr0wz (Exploit-DB, Web Archive).
Successful exploitation allows an attacker with local access to execute arbitrary code with the same privileges as the user running 10-Strike Network Inventory Explorer 8.54. This can result in full compromise of the affected system, including unauthorized access to sensitive inventory data, modification or deletion of system files, and disruption of application availability. The scope is limited to the local system, with no direct lateral movement capability, though post-exploitation access could facilitate further attacks within the network environment (Feedly, VulnCheck).
A proof-of-concept exploit for this vulnerability is publicly available on Exploit-DB (exploit #48253), and a detailed technical write-up was published by researcher whitecr0wz (Exploit-DB, Web Archive). Despite the public PoC, there is no evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.062%, indicating a low probability of exploitation in the near term. The vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
cmd.exe, powershell.exe, or network tools) following use of the 'Add' function.No official patch from 10-Strike Software has been confirmed for this vulnerability. Organizations should restrict local access to systems running 10-Strike Network Inventory Explorer 8.54 to trusted users only, and apply the principle of least privilege for application execution. Monitoring for suspicious activity related to the 'Add' function with unusual or oversized parameter inputs is recommended. Organizations should contact 10-Strike Software directly for security updates and consider evaluating alternative network inventory solutions if a patch remains unavailable (VulnCheck, Feedly).
The vulnerability received limited public attention, with automated alerts published by RedPacket Security and a mention in a CISA vulnerability bulletin for the week of February 2, 2026. No significant vendor statements or notable researcher commentary beyond the original whitecr0wz write-up have been identified (RedPacket Security, CISA Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."