A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2020-37138

CVE-2020-37138: 10-Strike Network Inventory RCE Flaw

CVE-2020-37138 is a buffer overflow RCE vulnerability in 10-Strike Network Inventory Explorer 9.03 allowing remote code execution via malicious file imports. This article covers technical details, impact analysis, and mitigation.

Updated: May 14, 2026

CVE-2020-37138 Overview

CVE-2020-37138 affects 10-Strike Network Inventory Explorer 9.03, a network asset management tool used to inventory hardware and software across enterprise networks. The vulnerability is a stack-based buffer overflow [CWE-121] in the application's file import functionality. An attacker who convinces a user to open a maliciously crafted text file can overwrite the Structured Exception Handler (SEH) on the stack. By chaining return-oriented programming (ROP) gadgets, the attacker bypasses Data Execution Prevention (DEP) and executes arbitrary code in the context of the running user.

Critical Impact

Successful exploitation grants arbitrary code execution on the local host with the privileges of the user running Network Inventory Explorer, enabling full compromise of confidentiality, integrity, and availability.

Affected Products

  • 10-Strike Network Inventory Explorer 9.03
  • 10-Strike Network Inventory Explorer (earlier 9.x builds sharing the vulnerable file-import routine)
  • Windows hosts running the vulnerable Network Inventory Explorer desktop client

Discovery Timeline

  • 2026-02-05 - CVE-2020-37138 published to NVD
  • 2026-04-15 - Last updated in NVD database

Technical Details for CVE-2020-37138

Vulnerability Analysis

The flaw resides in the routine that parses user-supplied text files imported into Network Inventory Explorer. The function copies attacker-controlled data into a fixed-size stack buffer without validating the input length. Oversized input corrupts adjacent stack frames, including the SEH record. When the application subsequently triggers an exception, control transfers to the attacker-controlled SEH handler pointer. Because DEP prevents direct shellcode execution on the stack, the public exploit uses a Structured Exception Handler Return-Oriented Programming (SEH-ROP) chain to pivot execution into a sequence of gadgets that mark memory executable and run shellcode. The vulnerability is tracked as CWE-121: Stack-based Buffer Overflow and requires user interaction to import the crafted file.

Root Cause

The root cause is missing bounds checking in the file-import parser. The application reads attacker-supplied data into a fixed-length stack buffer using an unsafe copy operation. No length validation is performed against the destination buffer size, allowing the saved return address and SEH chain to be overwritten. Lack of modern stack protections such as /GS cookies and SafeSEH on the vulnerable module makes the corrupted SEH record reliably exploitable.

Attack Vector

Exploitation requires local access with user interaction. An attacker delivers a crafted .txt or similar import file through phishing, a shared drive, or another delivery channel. When the victim uses the Network Inventory Explorer import feature to load the file, the parser triggers the overflow. The exploit overwrites the SEH handler with a pointer to a POP POP RET gadget located in an unprotected module, redirecting execution to a ROP chain that bypasses DEP and executes the embedded payload. Public exploit code is available as Exploit-DB entry 48264.

No verified source code for the vulnerable parser is publicly available. See Exploit-DB #48264 and the VulnCheck Advisory on Buffer Overflow for technical details and a working proof-of-concept.

Detection Methods for CVE-2020-37138

Indicators of Compromise

  • Unexpected child processes spawned by Network Inventory Explorer.exe, such as cmd.exe, powershell.exe, or rundll32.exe.
  • Crash events in the Windows Application event log referencing Network Inventory Explorer.exe with exception code 0xC0000005 (access violation) during file import.
  • Suspicious text or list files staged in user-writable directories immediately before launching the application.
  • Outbound network connections initiated by Network Inventory Explorer.exe to non-corporate destinations.

Detection Strategies

  • Hunt for process-lineage anomalies where Network Inventory Explorer.exe is the parent of interactive shells or scripting interpreters.
  • Monitor Windows Error Reporting (WER) and Application event channel for repeated faulting in the inventory application binary.
  • Inspect command-line arguments passed to the application for references to externally delivered import files.

Monitoring Recommendations

  • Forward endpoint process-creation telemetry (Sysmon Event ID 1, Windows Event ID 4688) to a central analytics platform for behavioral correlation.
  • Alert on module loads from user-writable paths into Network Inventory Explorer.exe.
  • Track file-write events that create .txt, .csv, or .lst files in directories immediately before the application is launched.

How to Mitigate CVE-2020-37138

Immediate Actions Required

  • Restrict use of 10-Strike Network Inventory Explorer 9.03 to trusted administrators on segmented management workstations.
  • Block the application from importing files originating from untrusted sources such as email attachments and external media.
  • Apply Microsoft Exploit Protection (formerly EMET) policies enforcing DEP, ASLR, and SEHOP for the Network Inventory Explorer.exe process.
  • Remove the software from endpoints where it is not actively required.

Patch Information

No vendor patch is referenced in the available advisory data. Consult the VulnCheck Advisory on Buffer Overflow and the 10-Strike Network Inventory Tool product page for the latest fixed release information. Upgrade to a version that addresses the file-import parsing flaw once available from the vendor.

Workarounds

  • Do not import text or list files received from untrusted sources into Network Inventory Explorer.
  • Run the application under a low-privilege user account with no administrative rights on the host.
  • Enable system-wide SEHOP through HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel\DisableExceptionChainValidation = 0 to harden against SEH overwrite exploits.
  • Application allow-listing should restrict execution of child processes spawned by the inventory binary.
bash
# Enable SEHOP system-wide on Windows to mitigate SEH-overwrite exploitation
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\kernel" /v DisableExceptionChainValidation /t REG_DWORD /d 0 /f

# Enable process-specific Exploit Protection mitigations via PowerShell
Set-ProcessMitigation -Name "Network Inventory Explorer.exe" -Enable DEP,SEHOP,ForceRelocateImages,BottomUp,HighEntropy

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeRCE

  • Vendor/Tech10 Strike Network Inventory Explorer

  • SeverityHIGH

  • CVSS Score8.4

  • EPSS Probability0.05%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Impact Assessment
  • ConfidentialityLow
  • IntegrityHigh
  • AvailabilityHigh
  • CWE References
  • CWE-121
  • Technical References
  • 10-Strike Homepage

  • 10-Strike Network Inventory Tool

  • Exploit-DB #48264

  • VulnCheck Advisory on Buffer Overflow
  • Related CVEs
  • CVE-2020-37142: 10-Strike Network Inventory Explorer RCE

  • CVE-2020-36961: 10-Strike Network Inventory RCE Flaw

  • CVE-2021-47772: Network Inventory Explorer RCE Vulnerability

  • CVE-2018-25344: 10-Strike Network Inventory Explorer Flaw
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English