


Perceptive Security
SOC/SIEM Consultancy

Free Desktop Clock 3.0 contains a stack overflow vulnerability in the Time Zones display name input that allows attackers to overwrite Structured Exception Hand…
Published:
4 februari 2026 om 23:00:00
Alert date:
5 februari 2026 om 18:08:45
Source:
nvd.nist.gov
Operating Systems
Free Desktop Clock 3.0 contains a critical stack overflow vulnerability in the Time Zones display name input functionality. The vulnerability allows attackers to overwrite Structured Exception Handler (SEH) registers through crafted malicious Unicode input. Successful exploitation can trigger access violations and potentially lead to arbitrary code execution. The vulnerability affects the desktop clock application's timezone display feature and represents a significant security risk for users of this software.
Technical details
Mitigation steps:
Affected products:
Free Desktop Clock
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2020-37126
http://www.drive-software.com
https://www.exploit-db.com/exploits/48314
https://www.vulncheck.com/advisories/free-desktop-clock-x-venetian-blinds-zipper-unicode-stack-overflow-seh
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
