CVE-2018-25219

PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that triggers code execution when pasted into the Licensed E-mail and Registration Code field during the registration process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:passfab:excel_password_recovery:*:*:*:*:*:*:*:*

History

31 Mar 2026, 15:07

Type Values Removed Values Added
References () https://www.exploit-db.com/exploits/46301 - () https://www.exploit-db.com/exploits/46301 - Exploit, VDB Entry
References () https://www.passfab.com/downloads/passfab-excel-password-recovery.exe - () https://www.passfab.com/downloads/passfab-excel-password-recovery.exe - Product
References () https://www.passfab.com/products/excel-password-recovery.html - () https://www.passfab.com/products/excel-password-recovery.html - Product
References () https://www.vulncheck.com/advisories/passfab-excel-password-recovery-seh-buffer-overflow - () https://www.vulncheck.com/advisories/passfab-excel-password-recovery-seh-buffer-overflow - Third Party Advisory
First Time Passfab excel Password Recovery
Passfab
CPE cpe:2.3:a:passfab:excel_password_recovery:*:*:*:*:*:*:*:*
Summary
  • (es) PassFab Excel Password Recovery 8.3.1 contiene una vulnerabilidad de desbordamiento de búfer de manejo de excepciones estructurado que permite a atacantes locales ejecutar código arbitrario al proporcionar una carga útil maliciosa en el campo de código de registro. Los atacantes pueden crear una carga útil de desbordamiento de búfer con un gadget pop-pop-ret y shellcode que desencadena la ejecución de código cuando se pega en el campo de correo electrónico con licencia y código de registro durante el proceso de registro.

26 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-26 14:16

Updated : 2026-03-31 15:07


NVD link : CVE-2018-25219

Mitre link : CVE-2018-25219

CVE.ORG link : CVE-2018-25219


JSON object : View

Products Affected

passfab

  • excel_password_recovery
CWE
CWE-787

Out-of-bounds Write