CVE-2018-25239

Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application.
Configurations

No configuration.

History

04 Apr 2026, 20:16

Type Values Removed Values Added
References
  • {'url': 'https://www.vulncheck.com/advisories/microsoft-smart-vpn-denial-of-service-via-search', 'source': 'disclosure@vulncheck.com'}
  • () https://www.vulncheck.com/advisories/smart-vpn-denial-of-service-via-search -

04 Apr 2026, 17:16

Type Values Removed Values Added
Summary (en) Microsoft Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application. (en) Smart VPN 1.1.3.0 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the search interface. Attackers can paste a buffer of 2100 characters into the top right search bar to trigger an unhandled exception that crashes the application.

04 Apr 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-04 14:16

Updated : 2026-04-16 16:15


NVD link : CVE-2018-25239

Mitre link : CVE-2018-25239

CVE.ORG link : CVE-2018-25239


JSON object : View

Products Affected

No product.

CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')