CVE-2017-20225 is a critical stack-based buffer overflow vulnerability (CWE-787) affecting TiEmu 2.08 and earlier versions, stemming from inadequate boundary checks on user-supplied input. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to execute arbitrary code remotely with low complexity by exploiting command-line arguments, potentially leading to complete system compromise. While no public exploit code is currently available on platforms like Metasploit or ExploitDB, and it is not listed in CISA's KEV catalog, there have been recent community discussions regarding its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.0.8CPE matchmatch criteria | cpe:2.3:a:ticalc:tiemu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.