CVE-2017-20225Disclosure(ticalc / tiemu)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can trigger the overflow through command-line arguments passed to the application, leveraging ROP gadgets to bypass protections and execute shellcode in the application context.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tiemu

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-28); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
tiemu

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-28: 3Mentions · 2026-03-29: 1PoC Mentioned / Linked · 2026-03-28: 1Technical Details · 2026-03-28: 303-2803-29
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-283
Disclosure3
2026-03-291
General1
Full discourse4 posts
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2017-20225: CRITICAL] Vulnerability in TiEmu 2.08 allows attackers to execute code via buffer overflow in user input, exploiting insufficient boundary checks. Risk of ROP gadget use for shellcode execut...#cve,CVE-2017-20225,#cybersecurity https://cvefind.com/CVE-2017-20225

    Post summary

    The tweet announces CVE‑2017‑20225 as a critical flaw in TiEmu 2.08, detailing a buffer-overflow vulnerability that could lead to code execution via ROP gadgets, but it does not provide any PoC or evidence of active exploitation.

    0001150
    617 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2017-20225 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-20225 #CVE-2017-20225 #CVE #Critical #CyberSecurity #InfoSec https://t.co/gZWiy4uW7v

    Post summary

    The tweet simply alerts to the existence of CVE-2017-20225 with a high severity score, but offers no technical specifics, exploitation evidence, or mitigation details.

    0000037
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2017-20225 TiEmu 2.08 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on … https://www.cve.org/CVERecord?id=CVE-2017-20225

    Post summary

    The snippet announces a stack‑based buffer overflow in TiEmu 2.08 and earlier, noting attackers could execute arbitrary code via inadequate boundary checks, but provides no PoC, exploit details, or patch information.

    0000050
    56.9K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2017-20225: TiEmu 2.08 Stack-Based Buffer Ov... Stack overflow with ROP bypass in a TI calculator emulator from 2008 - ancient codebase, trivial exploitation, perfect ... https://zerodaysignal.com/vulnerability/CVE-2017-20225 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2017‑20225 as a stack‑based buffer overflow in TiEmu 2.08 with a return‑oriented programming bypass, noting trivial exploitation potential, but does not provide a PoC or active exploitation evidence.

    0000042
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appticalctiemu---

Explore more