Junglewise Threat Intelligence

CVE-2020-37212: Nsasoft SpotMSN buffer overflow in registration name field

CVE-2020-37212 · Severity: high · CVSS 7.5 · Published 2026-02-11

Vendors: Nsasoft.

Executive brief

SpotMSN, a tool used for recovering MSN Messenger passwords, contains a flaw that allows the application to be crashed. An attacker can trigger this by entering an excessively long name into the registration field. This results in a denial of service, preventing the software from functioning correctly.

Technical details

A classic buffer overflow (CWE-120) exists in Nsasoft SpotMSN version 2.4.6 within the registration name input field. The vulnerability is triggered when the application fails to perform adequate bounds checking on the 'Name' field during the registration process. An attacker can exploit this by inputting a specially crafted payload of approximately 1,000 characters, leading to an application crash (Denial of Service). While some CVSS metrics suggest a network vector, the exploit typically requires local interaction where a user pastes the payload into the registration dialog on a Windows system. No official patch has been identified in the provided documentation.

Affected products

  • Nsasoft (Nsauditor) SpotMSN 2.4.6

Timeline

  • 2020-01-06: disclosed: Initial exploit PoC published by Ismail Tasdelen
  • 2026-02-11: advisory: NVD and VulnCheck advisory published

References