Junglewise Threat Intelligence

CVE-2020-37211: Nsasoft SpotIM buffer overflow in registration name field

CVE-2020-37211 · Severity: high · CVSS 7.5 · Published 2026-02-11

Vendors: Nsasoft.

Executive brief

Nsasoft SpotIM, a tool used for recovering instant messenger passwords, contains a flaw that allows the application to be crashed. An attacker can trigger this by entering an excessively long name into the software's registration field. This results in a denial-of-service condition where the application becomes unresponsive or closes unexpectedly, potentially disrupting password recovery operations.

Technical details

A classic buffer overflow (CWE-120) exists in Nsasoft SpotIM version 2.2 within the registration name input field. The vulnerability is triggered when the application fails to perform adequate bounds checking on the 'Name' field during the registration process. An attacker can achieve a denial-of-service (DoS) state by supplying a payload of approximately 1,000 characters, leading to an application crash. While some sources suggest a network vector, the primary exploit method involves local interaction with the application's registration interface on Windows 10. A public Proof of Concept (PoC) is available.

Affected products

  • Nsasoft SpotIM 2.2

Timeline

  • 2020-01-06: disclosed: Initial exploit code published on Exploit-DB
  • 2026-02-11: advisory: NVD publication date

References