CVE-2020-37040Disclosure

LOWCVSS 8.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially executing system commands like calc.exe.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-01-30); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-01-30: 1Mentions · 2026-02-01: 1Mentions · 2026-02-03: 1PoC Mentioned / Linked · 2026-02-01: 1Technical Details · 2026-01-30: 1Technical Details · 2026-02-01: 1Technical Details · 2026-02-03: 101-3002-0102-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    Code Blocks 17.12 has a local buffer overflow vulnerability (UBUNTU-CVE-2020-37040). Arbitrary code execution is possible via crafted Unicode filenames. Exercise caution with untrusted input. #CodeBlocks #bufferoverflow #infosec https://www.pulsepatch.io/posts/code-blocks-local-buffer-overflow-ubuntu-cve-2020-37040

    Post summary

    Code::Blocks 17.12 suffers a local buffer overflow that allows arbitrary code execution through crafted Unicode filenames. The post announces the flaw but offers no patches or exploit details.

    0000047
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Code Blocks 17.12 has a local buffer overflow (CVE-2020-37040) from crafted Unicode filenames. Exercise caution with untrusted input. #CodeBlocks #bufferoverflow #infosec https://www.pulsepatch.io/posts/code-blocks-local-buffer-overflow-cve-2020-37040

    Post summary

    The post announces a local buffer overflow (CVE-2020-37040) in Code Blocks 17.12 triggered by crafted Unicode filenames, with a cautionary note about untrusted input.

    0000049
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2020-37040 Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode charac… https://www.cve.org/CVERecord?id=CVE-2020-37040

    Post summary

    The text announces a local buffer overflow in Code Blocks 17.12 that enables arbitrary code execution through crafted Unicode file names, but it offers no PoC, exploit, or patch information.

    00000199
    56.5K followersView on X

Explore more