Home

Description

Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return-oriented programming chains for shell command execution.

PUBLISHED Reserved 2026-03-28 | Published 2026-03-28 | Updated 2026-03-30 | Assigner VulnCheck




HIGH: 8.6CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

Out-of-bounds Write

Product status

1.71.21
affected

Credits

Juan Sacco <juan.sacco@kpn.com> at KPN Red Team - http://www.kpn.com finder

References

www.exploit-db.com/exploits/42265 (ExploitDB-42265) exploit

www.flatassembler.net (Official Product Homepage) product

www.vulncheck.com/...sembler-stack-based-buffer-overflow-rop (VulnCheck Advisory: Flat Assembler 1.71.21 Stack-Based Buffer Overflow ROP) third-party-advisory

cve.org (CVE-2017-20228)

nvd.nist.gov (CVE-2017-20228)

Download JSON