Executive brief
Internet Download Manager is a popular Windows utility used to accelerate and schedule file downloads. A vulnerability in its scheduling component allows a local user to crash the application by entering an excessively long file path. This results in a denial-of-service condition, preventing the software from functioning correctly until it is restarted or the configuration is cleared.
Technical details
A classic buffer overflow (CWE-120) exists in the Scheduler component of Internet Download Manager version 6.38.12 and earlier. The vulnerability is triggered when a local attacker inputs more than 5,000 bytes into the 'Open the following file when done' configuration field. This lack of input validation leads to a memory corruption that crashes the application (denial of service). While the primary impact is application instability, proof-of-concept code indicates the overflow can overwrite structured exception handlers (SEH) on certain Windows versions, though no remote code execution has been confirmed. Users should update to the latest version of IDM to mitigate this issue.
Affected products
- Tonec Internet Download Manager <= 6.38.12
Timeline
- 2020-11-18: disclosed: Initial discovery and PoC by Vincent Wolterman
- 2020-11-19: other: Exploit-DB entry published
- 2026-05-16: advisory: NVD/VulnCheck advisory published