CVE-2018-25432

Arm Whois 3.11 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting the structured exception handler. Attackers can craft a malicious input file with a 672-byte offset to overwrite the nSEH and SEH pointers, enabling code execution through exception handler hijacking.
Configurations

No configuration.

History

22 Jul 2026, 08:10

Type Values Removed Values Added
Summary
  • (es) Arm Whois 3.11 contiene una vulnerabilidad de desbordamiento de búfer que permite a atacantes locales ejecutar código arbitrario sobrescribiendo el gestor de excepciones estructuradas. Los atacantes pueden crear un archivo de entrada malicioso con un desplazamiento de 672 bytes para sobrescribir los punteros nSEH y SEH, lo que permite la ejecución de código mediante el secuestro del gestor de excepciones.

01 Jun 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 22:16

Updated : 2026-07-22 08:10


NVD link : CVE-2018-25432

Mitre link : CVE-2018-25432

CVE.ORG link : CVE-2018-25432


JSON object : View

Products Affected

No product.

CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')