---
id: CVE-2017-20228
title: Flat Assembler 1.71.21 Stack-Based Buffer Overflow ROP
summary: >-
  Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability
  that allows local attackers to execute arbitrary code by supplying oversized
  input to the application. Attackers can craft malicious assembly input
  exceeding 589…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-787
vendor: Flatassembler
product: Flat Assembler
affected:
  - flat_assembler 1.71.21
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-30T17:22:15.300385Z'
exploitAvailable: true
published: '2026-03-28'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:00.746Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2017-20228'
references:
  - url: 'https://www.exploit-db.com/exploits/42265'
    label: ExploitDB-42265
  - url: 'http://www.flatassembler.net'
    label: Official Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/flat-assembler-stack-based-buffer-overflow-rop
    label: 'VulnCheck Advisory: Flat Assembler 1.71.21 Stack-Based Buffer Overflow ROP'
tags:
  - cve.org
  - exploit-available
epss: 0.00219
epssPercentile: 0.11182
ingestedAt: '2026-10-01T15:48:17.893Z'
---

## Overview

Flat Assembler 1.71.21 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input to the application. Attackers can craft malicious assembly input exceeding 5895 bytes to overwrite the instruction pointer and execute return-oriented programming chains for shell command execution.

## Affected

- `flat_assembler 1.71.21`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
