Junglewise Threat Intelligence

CVE-2020-37207: Nsasoft SpotDialup buffer overflow in registration key field

CVE-2020-37207 · Severity: high · CVSS 7.5 · Published 2026-02-11

Vendors: Nsasoft.

Executive brief

SpotDialup, a tool used for recovering dial-up and VPN passwords, contains a flaw that allows the application to be crashed. An attacker can trigger this by entering an excessively long registration key into the software's activation field. This results in a denial-of-service, preventing legitimate users from using the application on the affected machine.

Technical details

A classic buffer overflow (CWE-120) exists in SpotDialup 1.6.7 within the registration key input mechanism. The application fails to perform adequate bounds checking on the 'Key' field during the registration process. An attacker can trigger a crash by supplying a 1,000-character string, leading to a denial-of-service condition. While some metrics suggest a network vector, the exploit typically requires local interaction where a user or attacker pastes the malicious payload into the application's GUI on a Windows system. A public Proof of Concept (PoC) exists.

Affected products

  • Nsasoft (NSAuditor) SpotDialup 1.6.7

Timeline

  • 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
  • 2026-02-11: advisory: NVD publication date

References