CVE-2020-23060: Tonec Internet Download Manager

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.

Affected products

  • Tonec Internet Download Manager: version 6.37.11.1 only

Published 2021-10-22. Last modified 2026-06-17.