← Vulnerability feed

Vulnerability record · CVE-2020-13580 · published 4 February 2021

CVE-2020-13580: SoftMaker PlanMaker heap buffer overflow via crafted document

Softmaker · Planmaker 2021

SoftMaker Office 2021's PlanMaker application has a heap-based buffer overflow in its document parsing functionality. The parser trusts a length value from a particular record type and uses it to write a 16-bit null relative to a stack-allocated buffer without bounds checking, allowing controlled memory corruption. Opening a malicious document can lead to code execution in the context of the application.

7.8 CVSS 3.1 High EPSS 71% · top 0.6% CWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 6.8
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser to explicitly trust a length from a particular record type and use it to write a 16-bit null relative to a buffer allocated on the stack. Due to a lack of bounds-checking on this value, this can allow an attacker to write to memory outside of the buffer and controllably corrupt memory. This can allow an attacker to earn code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus a very high EPSS score and public exploit-tagged technical details make this a serious client-side code execution risk.

What it is

SoftMaker Office 2021's PlanMaker application has a heap-based buffer overflow in its document parsing functionality. The parser trusts a length value from a particular record type and uses it to write a 16-bit null relative to a stack-allocated buffer without bounds checking, allowing controlled memory corruption. Opening a malicious document can lead to code execution in the context of the application.

Impact

An attacker who gets a victim to open a crafted document can corrupt memory controllably and potentially execute arbitrary code under the PlanMaker process. This gives the attacker the privileges of the user running the application.

Attack surface

The vulnerability is reached locally by opening a specially crafted PlanMaker document; the CVSS vector indicates no privileges are required but user interaction is needed to open the file. No network vector is described.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at 0.70688 (99.36th percentile) and the references are tagged Exploit and Technical Description, indicating public technical detail and exploit potential.

What to do

  • Apply the vendor patch for SoftMaker Office 2021 PlanMaker as soon as it is available.
  • Do not open untrusted or unsolicited PlanMaker documents; treat them as executable content.
  • Use email and web gateways to block or sandbox PlanMaker document attachments from external sources.
  • Run PlanMaker with least privilege and consider application isolation or sandboxing for document parsing.
  • Monitor vendor advisories for updated fixed versions and verify installed build numbers.

Detection

  • Monitor for PlanMaker processes spawning child processes or making unexpected network connections after opening documents.
  • Collect and review crash dumps or application error reports from PlanMaker involving heap corruption or access violations.
  • Track file creation or download of PlanMaker documents from email clients, browsers, or removable media followed by PlanMaker execution.
  • Use endpoint detection to flag anomalous memory write behavior or exploitation patterns in the PlanMaker process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1191 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1191 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2020-13580 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-28587Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 0.95%7.8CVE-2020-13581Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…EPSS 1.0%7.8CVE-2020-27250Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…EPSS 0.95%7.8CVE-2020-13586Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker …EPSS 1.5%7.8CVE-2020-27247Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-27248Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-27249Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-13579SoftMaker PlanMaker document parsing integer overflow leads to heap overflowSoftMaker Office 2021's PlanMaker application has an integer overflow in its document parsing code. A crafted document causes arithmetic to overflow,…EPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13580), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.