CVE-2019-25633

AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input through the email preferences and report wizard interfaces. Attackers can inject crafted payloads into the Display name field and Load from file parameter to trigger the overflow and execute shellcode with application privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:aida64:aida64:5.99.4900:*:*:*:extreme:*:*:*

History

17 Jun 2026, 02:32

Type Values Removed Values Added
Summary
  • (es) AIDA64 Extreme 5.99.4900 contiene una vulnerabilidad de desbordamiento de búfer de manejo estructurado de excepciones que permite a atacantes locales ejecutar código arbitrario al suministrar entrada maliciosa a través de las interfaces de preferencias de correo electrónico y asistente de informes. Los atacantes pueden inyectar cargas útiles manipuladas en el campo Display name y el parámetro Load from file para activar el desbordamiento y ejecutar shellcode con privilegios de aplicación.

26 Mar 2026, 16:40

Type Values Removed Values Added
References () http://download.aida64.com/aida64extreme599.exe - () http://download.aida64.com/aida64extreme599.exe - Product
References () https://www.aida64.com - () https://www.aida64.com - Product
References () https://www.exploit-db.com/exploits/46636 - () https://www.exploit-db.com/exploits/46636 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/aida64-extreme-seh-buffer-overflow-via-egghunter - () https://www.vulncheck.com/advisories/aida64-extreme-seh-buffer-overflow-via-egghunter - Third Party Advisory
CPE cpe:2.3:a:aida64:aida64:5.99.4900:*:*:*:extreme:*:*:*
First Time Aida64 aida64
Aida64

24 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-24 12:16

Updated : 2026-06-17 02:32


NVD link : CVE-2019-25633

Mitre link : CVE-2019-25633

CVE.ORG link : CVE-2019-25633


JSON object : View

Products Affected

aida64

  • aida64
CWE
CWE-787

Out-of-bounds Write