Vulnerability record · CVE-2020-13580 · published 4 February 2021
CVE-2020-13580: SoftMaker PlanMaker heap buffer overflow via crafted document
Softmaker · Planmaker 2021
SoftMaker Office 2021's PlanMaker application has a heap-based buffer overflow in its document parsing functionality. The parser trusts a length value from a particular record type and uses it to write a 16-bit null relative to a stack-allocated buffer without bounds checking, allowing controlled memory corruption. Opening a malicious document can lead to code execution in the context of the application.
Description
An exploitable heap-based buffer overflow vulnerability exists in the PlanMaker document parsing functionality of SoftMaker Office 2021’s PlanMaker application. A specially crafted document can cause the document parser to explicitly trust a length from a particular record type and use it to write a 16-bit null relative to a buffer allocated on the stack. Due to a lack of bounds-checking on this value, this can allow an attacker to write to memory outside of the buffer and controllably corrupt memory. This can allow an attacker to earn code execution under the context of the application. An attacker can entice the victim to open a document to trigger this vulnerability.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus a very high EPSS score and public exploit-tagged technical details make this a serious client-side code execution risk.
What it is
SoftMaker Office 2021's PlanMaker application has a heap-based buffer overflow in its document parsing functionality. The parser trusts a length value from a particular record type and uses it to write a 16-bit null relative to a stack-allocated buffer without bounds checking, allowing controlled memory corruption. Opening a malicious document can lead to code execution in the context of the application.
Impact
An attacker who gets a victim to open a crafted document can corrupt memory controllably and potentially execute arbitrary code under the PlanMaker process. This gives the attacker the privileges of the user running the application.
Attack surface
The vulnerability is reached locally by opening a specially crafted PlanMaker document; the CVSS vector indicates no privileges are required but user interaction is needed to open the file. No network vector is described.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is high at 0.70688 (99.36th percentile) and the references are tagged Exploit and Technical Description, indicating public technical detail and exploit potential.
What to do
- Apply the vendor patch for SoftMaker Office 2021 PlanMaker as soon as it is available.
- Do not open untrusted or unsolicited PlanMaker documents; treat them as executable content.
- Use email and web gateways to block or sandbox PlanMaker document attachments from external sources.
- Run PlanMaker with least privilege and consider application isolation or sandboxing for document parsing.
- Monitor vendor advisories for updated fixed versions and verify installed build numbers.
Detection
- Monitor for PlanMaker processes spawning child processes or making unexpected network connections after opening documents.
- Collect and review crash dumps or application error reports from PlanMaker involving heap corruption or access violations.
- Track file creation or download of PlanMaker documents from email clients, browsers, or removable media followed by PlanMaker execution.
- Use endpoint detection to flag anomalous memory write behavior or exploitation patterns in the PlanMaker process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1191 | ExploitTechnical DescriptionThird Party Advisory |
| https://talosintelligence.com/vulnerability_reports/TALOS-2020-1191 | ExploitTechnical DescriptionThird Party Advisory |
Track CVE-2020-13580 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-13580), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.