Denial of Service Vulnerability in VirtualTablet Server by Sunny Side Software
CVE-2020-37085
Key Information:
- Vendor
Sunnysidesoft
- Status
- Vendor
- CVE Published:
- 3 February 2026
Badges
What is CVE-2020-37085?
VirtualTablet Server version 3.0.2 is susceptible to a denial of service vulnerability, which can be exploited by attackers sending oversized string payloads via the Thrift protocol. By invoking the send_say() method with a lengthy string, attackers may render the server unresponsive, disrupting service and affecting users reliant on its functionality.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
VirtualTablet Server 3.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
