CVE-2018-25232

Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log files location field. Attackers can input a buffer of 2000 characters in the Log Files Location custom path parameter to trigger a crash when the OK button is clicked.
Configurations

Configuration 1 (hide)

cpe:2.3:a:softros:softros_lan_messenger:*:*:*:*:*:*:*:*

History

08 Apr 2026, 16:54

Type Values Removed Values Added
CPE cpe:2.3:a:softros:softros_lan_messenger:*:*:*:*:*:*:*:*
First Time Softros softros Lan Messenger
Softros
Summary
  • (es) Softros LAN Messenger 9.2 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al proporcionar una cadena excesivamente larga al campo de ubicación de archivos de registro personalizados. Los atacantes pueden introducir un búfer de 2000 caracteres en el parámetro de ruta personalizada Log Files Location para provocar un bloqueo cuando se hace clic en el botón Aceptar.
References () https://messenger.softros.com/ - () https://messenger.softros.com/ - Product
References () https://messenger.softros.com/downloads/ - () https://messenger.softros.com/downloads/ - Product
References () https://www.exploit-db.com/exploits/45781 - () https://www.exploit-db.com/exploits/45781 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/softros-lan-messenger-denial-of-service-via-log-files-location - () https://www.vulncheck.com/advisories/softros-lan-messenger-denial-of-service-via-log-files-location - Third Party Advisory

30 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 12:16

Updated : 2026-04-08 16:54


NVD link : CVE-2018-25232

Mitre link : CVE-2018-25232

CVE.ORG link : CVE-2018-25232


JSON object : View

Products Affected

softros

  • softros_lan_messenger
CWE
CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input