CVE-2019-25627

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.
Configurations

Configuration 1 (hide)

cpe:2.3:a:flexhex:flexhex:2.71:*:*:*:*:*:*:*

History

15 Apr 2026, 16:10

Type Values Removed Values Added
CPE cpe:2.3:a:flexhex:flexhex:2.71:*:*:*:*:*:*:*
References () http://www.flexhex.com - () http://www.flexhex.com - Broken Link, Product
References () http://www.flexhex.com/download/flexhex_setup.exe - () http://www.flexhex.com/download/flexhex_setup.exe - Broken Link, Product
References () https://www.exploit-db.com/exploits/46665 - () https://www.exploit-db.com/exploits/46665 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/flexhex-local-buffer-overflow-via-seh-unicode - () https://www.vulncheck.com/advisories/flexhex-local-buffer-overflow-via-seh-unicode - Third Party Advisory
Summary
  • (es) FlexHEX 2.71 contiene una vulnerabilidad local de desbordamiento de búfer en el campo Stream Name que permite a atacantes locales ejecutar código arbitrario al desencadenar un desbordamiento del gestor de excepciones estructuradas (SEH). Los atacantes pueden crear un archivo de texto malicioso con shellcode y punteros de cadena SEH cuidadosamente alineados, pegar el contenido en el diálogo Stream Name, y ejecutar comandos arbitrarios como calc.exe cuando se desencadena el gestor de excepciones.
First Time Flexhex flexhex
Flexhex

24 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 12:16

Updated : 2026-04-15 16:10


NVD link : CVE-2019-25627

Mitre link : CVE-2019-25627

CVE.ORG link : CVE-2019-25627


JSON object : View

Products Affected

flexhex

  • flexhex
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type