CVE-2019-25563

PCHelpWareV2 1.0.0.5 contains a denial of service vulnerability that allows local attackers to crash the application by supplying a malformed image file. Attackers can trigger the vulnerability through the Create SC feature by selecting a crafted BMP file with an oversized buffer, causing the application to crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:uvnc:pchelpwarev2:1.0.0.5:*:*:*:*:*:*:*

History

24 Mar 2026, 20:47

Type Values Removed Values Added
Summary
  • (es) PCHelpWareV2 1.0.0.5 contiene una vulnerabilidad de denegación de servicio que permite a atacantes locales bloquear la aplicación al proporcionar un archivo de imagen malformado. Los atacantes pueden activar la vulnerabilidad a través de la función Create SC al seleccionar un archivo BMP manipulado con un búfer sobredimensionado, lo que provoca el bloqueo de la aplicación.
CPE cpe:2.3:a:uvnc:pchelpwarev2:1.0.0.5:*:*:*:*:*:*:*
First Time Uvnc pchelpwarev2
Uvnc
References () http://www.uvnc.eu/download/pchw2/PCHelpWareV2.msi - () http://www.uvnc.eu/download/pchw2/PCHelpWareV2.msi - Product
References () https://www.exploit-db.com/exploits/46708 - () https://www.exploit-db.com/exploits/46708 - Exploit, Third Party Advisory, VDB Entry
References () https://www.uvnc.com/home.html - () https://www.uvnc.com/home.html - Product
References () https://www.vulncheck.com/advisories/pchelpwarev2-denial-of-service-via-sc-creation - () https://www.vulncheck.com/advisories/pchelpwarev2-denial-of-service-via-sc-creation - Third Party Advisory

21 Mar 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-21 13:16

Updated : 2026-03-24 20:47


NVD link : CVE-2019-25563

Mitre link : CVE-2019-25563

CVE.ORG link : CVE-2019-25563


JSON object : View

Products Affected

uvnc

  • pchelpwarev2
CWE
CWE-226

Sensitive Information in Resource Not Removed Before Reuse