CVE-2020-37040: Code::blocks
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Code Blocks 17.12 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious file name with Unicode characters. Attackers can trigger the vulnerability by pasting a specially crafted payload into the file name field during project creation, potentially executing system commands like calc.exe.
Affected products
- Code::blocks Code::blocks: version 17.12 only
Published 2026-01-30. Last modified 2026-06-17.