Vulnerability record · CVE-2020-13579 · published 4 February 2021
CVE-2020-13579: SoftMaker PlanMaker document parsing integer overflow leads to heap overflow
Softmaker · Planmaker 2021
SoftMaker Office 2021's PlanMaker application has an integer overflow in its document parsing code. A crafted document causes arithmetic to overflow, producing an undersized heap allocation that is then overrun when file data is copied into it, corrupting memory. Because the flaw is reachable by opening a document, it is a realistic client-side code execution risk.
Description
An exploitable integer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser perform arithmetic that may overflow which can result in an undersized heap allocation. Later when copying data from the file into this allocation, a heap-based buffer overflow will occur which can corrupt memory. These types of memory corruptions can allow for code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with user-interaction-only reachability and a high EPSS score make this a serious client-side risk, though it is not in KEV and no active exploitation is documented.
What it is
SoftMaker Office 2021's PlanMaker application has an integer overflow in its document parsing code. A crafted document causes arithmetic to overflow, producing an undersized heap allocation that is then overrun when file data is copied into it, corrupting memory. Because the flaw is reachable by opening a document, it is a realistic client-side code execution risk.
Impact
An attacker can corrupt heap memory and potentially execute code in the context of the PlanMaker application, giving the same privileges as the user running it.
Attack surface
Reached locally by opening a malicious PlanMaker document; the CVSS vector shows no privileges required but user interaction is required, since the victim must open the file.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is high (about 0.71, 99th percentile) and the Talos reference is tagged Exploit, indicating public exploit-related detail exists.
What to do
- Update SoftMaker Office 2021 / PlanMaker to a version that fixes the parsing flaw.
- Block or quarantine untrusted PlanMaker documents at email and web gateways until patched.
- Open documents from unknown senders in a sandboxed or isolated environment.
- Enable exploit mitigations such as ASLR and DEP and keep endpoint protection current.
Detection
- Monitor for PlanMaker processes spawning unexpected child processes or making unusual network connections.
- Look for crashes or abnormal termination of PlanMaker when opening documents.
- Scan email and file shares for PlanMaker documents from untrusted sources and alert on their delivery.
- Use endpoint telemetry to detect heap corruption indicators or exploit-mitigation events tied to PlanMaker.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1190 | ExploitTechnical DescriptionThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1190 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2020-13579 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13579), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.