CVE-2018-25219
8.4PassFab · Excel Password Recovery
PassFab Excel Password Recovery 8.3.1 is vulnerable to a structured exception handling buffer overflow, allowing local attackers to execute arbitrary code via a malicious registration code payload.
Executive summary
A critical local buffer overflow vulnerability in PassFab Excel Password Recovery 8.3.1 allows an attacker to achieve arbitrary code execution on the host system.
Vulnerability
This is a structured exception handling (SEH) buffer overflow (CWE-787) triggered when a malicious payload is supplied to the Licensed E-mail and Registration Code field. The vulnerability can be exploited by an unauthenticated local user during the registration process.
Business impact
Successful exploitation of this vulnerability allows for arbitrary code execution with the privileges of the user running the application. This could lead to full system compromise, unauthorized data access, or the deployment of malware on the local machine. Given the CVSS score of 8.4, this represents a significant risk to workstations where this software is installed.
Remediation
Immediate Action: There is currently no official patch available from the vendor. Users should uninstall the software immediately or restrict access to the application to prevent unauthorized execution.
Proactive Monitoring: Review host-based security logs for abnormal process crashes or attempts to execute unauthorized binaries associated with the application directory.
Compensating Controls: Implement strict application control policies (e.g., AppLocker or equivalent) to prevent the execution of untrusted software or unauthorized payloads on end-user systems.
Exploitation status
Public Exploit Available: Yes, a functional local exploit exists as documented on Exploit-DB (EDB-ID: 46301).
Analyst recommendation
Due to the lack of an available vendor patch and the presence of a published public exploit, this software poses an unacceptable security risk. Organizations should identify all instances of PassFab Excel Password Recovery 8.3.1 within their environment and remove the software until the vendor provides a confirmed fix.
Sources
Originally found and disclosed by Achilles, per the CVE Program record.
- ExploitDB-46301 Exploit / PoC
- Official Product Homepage
- Product Reference
- VulnCheck Advisory: PassFab Excel Password Recovery 8.3.1 SEH Buffer Overflow Third-party advisory