Vulnerability record · CVE-2014-2206 · published 5 March 2014
CVE-2014-2206: GetGo Download Manager HTTP response header stack buffer overflow
GGetgosoft · Getgo Download Manager
GetGo Download Manager versions 4.9.0.1982, 4.8.2.1346, 4.4.5.502 and earlier contain a stack-based buffer overflow (CWE-119) triggered by a long HTTP response header. A remote attacker who controls or influences a server response can crash the client and potentially execute arbitrary code in the context of the user running the download manager.
Description
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a long HTTP Response Header.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe vulnerability is remotely reachable with no authentication, has a CVSS 2.0 base score of 10, and public exploit references plus a very high EPSS score indicate active risk, though it affects an older download manager.
What it is
GetGo Download Manager versions 4.9.0.1982, 4.8.2.1346, 4.4.5.502 and earlier contain a stack-based buffer overflow (CWE-119) triggered by a long HTTP response header. A remote attacker who controls or influences a server response can crash the client and potentially execute arbitrary code in the context of the user running the download manager.
Impact
Successful exploitation can crash the application and, per the description, allow execution of arbitrary code on the victim host, giving the attacker the privileges of the logged-in user.
Attack surface
The flaw is reached over the network when the download manager processes an HTTP response header from a server, requiring no authentication; the victim must initiate a download or otherwise cause the client to fetch a response from an attacker-controlled or compromised server.
Exploitation
CISA KEV does not list this CVE, but public references are tagged Exploit and EPSS reports a 30-day probability of 0.6144 (99.1st percentile), indicating a high likelihood of exploitation activity.
What to do
- Upgrade GetGo Download Manager to a version later than 4.9.0.1982, or remove the product if no fixed release exists.
- Restrict or block downloads from untrusted or attacker-controllable servers until the client is patched.
- Run the download manager with least privilege so code execution does not inherit administrative rights.
- Apply network egress filtering and proxy inspection to limit contact with malicious HTTP servers.
- Monitor vendor channels for a patched release, since the record does not name a fixed version.
Detection
- Monitor for crashes of the GetGo Download Manager process, especially during or immediately after HTTP downloads.
- Inspect proxy and network logs for unusually long or malformed HTTP response headers reaching download clients.
- Use endpoint detection to flag suspicious child processes spawned by the download manager.
- Correlate download manager crash events with subsequent process creation or outbound connections from the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2014-2206 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-2206), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.