CVE-2017-20229Disclosure(invisible-island / mawk)

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks on user-supplied input. Attackers can craft malicious input that overflows the stack buffer and execute a return-oriented programming chain to spawn a shell with application privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mawk

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-28); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Products
mawk

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-28: 3Mentions · 2026-03-29: 2Technical Details · 2026-03-28: 3Technical Details · 2026-03-29: 203-2803-29
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-283
Disclosure3
2026-03-292
Disclosure1General1
Full discourse5 posts
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2018-25220 | CVSS 9.8 🔴 CVE-2017-20229 | CVSS 9.8 🔴 CVE-2018-25223 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high‑score CVEs with their CVSS ratings, but offers no details on PoCs, exploit code, active exploitation, patches, or debunking. It serves merely as a brief reference to these vulnerabilities.

    0000028
    5.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2017-20229 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2017-20229 #CVE-2017-20229 #CVE #Critical #CyberSecurity #InfoSec https://t.co/th2csdUFSP

    Post summary

    The tweet announces CVE-2017-20229 as a critical vulnerability with a 9.8 severity score but offers no technical exploitation details, patches, or PoC.

    0000025
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2017-20229 MAWK 1.3.3-17 and prior contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting inadequate boundary checks … https://www.cve.org/CVERecord?id=CVE-2017-20229

    Post summary

    The text announces a stack-based buffer overflow in MAWK 1.3.3-17 and earlier, enabling arbitrary code execution via inadequate boundary checks.

    0000033
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2017-20229: CRITICAL] Vulnerability in MAWK 1.3.3-17 and earlier versions allows attackers to execute arbitrary code via stack-based buffer overflow from inadequate boundary checks on user input.#cve,CVE-2017-20229,#cybersecurity https://cvefind.com/CVE-2017-20229

    Post summary

    The tweet announces CVE‑2017‑20229 as a critical stack‑based buffer overflow in MAWK that permits arbitrary code execution, but offers no PoC, exploit code, or mitigation details.

    0000020
    617 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2017-20229: MAWK 1.3.3-17 Stack-Based Buffer... ROP chains against a text processor that's probably embedded in half your shell scripts - MAWK's stack smashing turns a... https://zerodaysignal.com/vulnerability/CVE-2017-20229 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    This post announces the discovery of a stack-based buffer overflow (CVE‑2017‑20229) in MAWK, providing a link for further details but no PoC, exploit code, or mitigation information.

    0000040
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appinvisible-islandmawk---

Explore more