CVE-2019-25631

AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. Attackers can inject egg hunter shellcode through the SMTP display name field in preferences or report wizard functionality to trigger the overflow and execute code with application privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aida64:aida64:5.99.4900:*:*:*:business:*:*:*

History

27 Mar 2026, 16:59

Type Values Removed Values Added
CPE cpe:2.3:a:aida64:aida64:5.99.4900:*:*:*:business:*:*:*
First Time Aida64 aida64
Aida64
References () https://www.aida64.com - () https://www.aida64.com - Product
References () https://www.aida64.com/downloads - () https://www.aida64.com/downloads - Product
References () https://www.exploit-db.com/exploits/46639 - () https://www.exploit-db.com/exploits/46639 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/aida64-business-seh-buffer-overflow-via-egghunter - () https://www.vulncheck.com/advisories/aida64-business-seh-buffer-overflow-via-egghunter - Third Party Advisory
Summary
  • (es) AIDA64 Business 5.99.4900 contiene una vulnerabilidad de desbordamiento de búfer de manejo de excepciones estructurado que permite a atacantes locales ejecutar código arbitrario sobrescribiendo punteros SEH con shellcode malicioso. Los atacantes pueden inyectar shellcode egg hunter a través del campo de nombre para mostrar de SMTP en las preferencias o la funcionalidad del asistente de informes para activar el desbordamiento y ejecutar código con privilegios de aplicación.

24 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 12:16

Updated : 2026-03-27 16:59


NVD link : CVE-2019-25631

Mitre link : CVE-2019-25631

CVE.ORG link : CVE-2019-25631


JSON object : View

Products Affected

aida64

  • aida64
CWE
CWE-787

Out-of-bounds Write