CVE-2020-37193

7.5

Top Password Software · ZIP Password Recovery

ZIP Password Recovery 2.30 is susceptible to a denial of service vulnerability caused by a buffer overflow, allowing attackers to crash the application via maliciously crafted input.

Executive summary

A buffer overflow vulnerability in Top Password Software ZIP Password Recovery 2.30 allows an attacker to cause a denial of service by providing a specially crafted input file.

Vulnerability

The application is vulnerable to a buffer overflow (CWE-120) when processing input. An unauthenticated attacker can trigger an application crash by providing a maliciously crafted text file when prompted to select a ZIP file for processing.

Business impact

The primary impact of this vulnerability is a denial of service, which renders the software unusable and disrupts business workflows relying on password recovery operations. While the CVSS score of 7.5 reflects a significant impact on service availability, the requirement for user interaction limits the risk to scenarios where a victim is enticed to process a malicious file. Such disruptions can lead to operational delays and may be used as a component in more complex attack chains.

Remediation

Immediate Action: As there is no official patch currently available, users should restrict the use of this software to trusted files only and avoid processing files from untrusted or unknown sources.

Proactive Monitoring: Monitor local system event logs for repeated application crashes or unexpected terminations of the ZIP Password Recovery process.

Compensating Controls: Ensure that endpoint protection software is active to identify and block the execution of potentially malicious files or scripts that might be used to trigger the overflow.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists via the Exploit Database (EDB-ID: 47894).

Analyst recommendation

Given the availability of a public proof of concept and the lack of a vendor patch, organizations should exercise caution when using this product. Users should treat all input files with suspicion and consider migrating to alternative, actively maintained password recovery solutions if this software cannot be secured or isolated from untrusted inputs.

Sources

Originally found and disclosed by ZwX, per the CVE Program record.