← Vulnerability feed

Vulnerability record · CVE-2020-13586 · published 4 February 2021

CVE-2020-13586: Softmaker planmaker 2021 heap-based buffer overflow vulnerability

Softmaker · Planmaker 2021

A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014). A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

7.8 CVSS 3.1 High EPSS 1.5% · top 26.4% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
7.8CVSS 3.1 base score, v2 6.8
1.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A memory corruption vulnerability exists in the Excel Document SST Record 0x00fc functionality of SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014). A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1197 ExploitTechnical DescriptionThird Party Advisory
https://talosintelligence.com/vulnerability_reports/TALOS-2020-1197 ExploitTechnical DescriptionThird Party Advisory

Track CVE-2020-13586 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2020-28587Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 0.95%7.8CVE-2020-13581Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…EPSS 1.0%7.8CVE-2020-27250Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityIn SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014), a specially crafted document can cause the document parser to copy data f…EPSS 0.95%7.8CVE-2020-27247Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-27248Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-27249Softmaker planmaker 2021 heap-based buffer overflow vulnerabilityA specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object tha…EPSS 1.2%7.8CVE-2020-13579SoftMaker PlanMaker document parsing integer overflow leads to heap overflowSoftMaker Office 2021's PlanMaker application has an integer overflow in its document parsing code. A crafted document causes arithmetic to overflow,…EPSS 71%analysed7.8CVE-2020-13580SoftMaker PlanMaker heap buffer overflow via crafted documentSoftMaker Office 2021's PlanMaker application has a heap-based buffer overflow in its document parsing functionality. The parser trusts a length valu…EPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2020-13586), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.