Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25627

Опубликовано: 24 мар. 2026
Источник: nvd
CVSS3: 8.4
CVSS3: 7.8
EPSS Низкий

Описание

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:flexhex:flexhex:2.71:*:*:*:*:*:*:*

EPSS

Процентиль: 18%
0.00257
Низкий

8.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.4
github
6 месяцев назад

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

EPSS

Процентиль: 18%
0.00257
Низкий

8.4 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-434