Junglewise Threat Intelligence

CVE-2020-37210: Nsasoft SpotIE buffer overflow in registration key input

CVE-2020-37210 · Severity: high · CVSS 7.5 · Published 2026-02-11

Vendors: Nsasoft.

Executive brief

SpotIE, a tool used for recovering Internet Explorer passwords and browser history, contains a flaw that allows the application to be crashed. An attacker can trigger this by entering an excessively long string of characters into the registration key field. This results in a denial of service, preventing legitimate users from using the software on the affected machine.

Technical details

A classic buffer overflow (CWE-120) exists in Nsasoft SpotIE version 2.9.5 and earlier. The vulnerability is located in the 'Key' input field within the registration dialog, which fails to properly validate the length of the input buffer. An attacker can trigger the vulnerability by supplying a payload of approximately 1,000 characters, leading to an application crash. While some CVSS metrics suggest a network vector, the exploit typically requires local interaction where a user or attacker pastes the malicious string into the software's registration interface. A public Proof of Concept (PoC) is available.

Affected products

  • Nsasoft (NSAuditor) SpotIE 2.9.5 and earlier

Timeline

  • 2020-01-06: disclosed: Initial exploit PoC published on Exploit-DB
  • 2026-02-11: advisory: NVD/VulnCheck advisory published

References