Junglewise Threat Intelligence

CVE-2020-37131: Nsauditor Product Key Explorer buffer overflow in registration key field

CVE-2020-37131 · Severity: medium · CVSS 6.2 · Published 2026-02-05

Vendors: Nsasoft.

Executive brief

Nsauditor Product Key Explorer, a tool used to recover and backup software activation keys, is susceptible to a flaw that allows a local user to crash the software. By entering an excessively long registration key into the application's activation field, the program will stop responding or shut down unexpectedly. This results in a denial of service for the local user, preventing them from using the software's recovery features.

Technical details

A classic buffer overflow (CWE-120) exists in Nsauditor Product Key Explorer version 4.2.2.0. The vulnerability is located in the 'Enter Registration Code' component, specifically within the 'Key' input field, which fails to properly validate the length of the input string. A local attacker can trigger this vulnerability by pasting a specially crafted payload of approximately 1,000 bytes into the field. This results in an application crash (Denial of Service). While the current exploit demonstrates a crash, buffer overflows of this nature can sometimes be leveraged for broader memory corruption. No official patch is noted in the advisory, though the vulnerability was publicly disclosed with a Proof of Concept (PoC).

Affected products

  • Nsauditor Product Key Explorer 4.2.2.0

Timeline

  • 2020-04-04: disclosed: Vulnerability discovered by 0xMoHassan
  • 2020-04-06: other: PoC exploit published on Exploit-DB
  • 2026-02-05: advisory: NVD/VulnCheck advisory published

References