CVE-2018-25304

8.4

Free Download Manager · Free Download Manager

Free Download Manager 2.0 Build 417 contains a local buffer overflow vulnerability in the URL import feature, allowing attackers to execute arbitrary code via a malicious URL file.

Executive summary

A local buffer overflow vulnerability in Free Download Manager 2.0 Build 417 allows for arbitrary code execution, posing a significant risk to affected workstations.

Vulnerability

This is a classic buffer overflow (CWE-120) triggered by the application's URL import functionality. An unauthenticated attacker can exploit this by crafting a malicious Location header in a response that, when processed by the software, overwrites the structured exception handler (SEH) chain.

Business impact

The vulnerability allows an attacker to achieve arbitrary code execution on a user's machine, which could lead to full system compromise, data exfiltration, or the installation of persistent malware. Given the high CVSS score of 8.4, the risk of total system takeover is severe, particularly for users who frequently process untrusted download lists.

Remediation

Immediate Action: Users should immediately uninstall or upgrade to a supported, modern version of Free Download Manager that is not affected by this legacy vulnerability.

Proactive Monitoring: Security teams should monitor endpoint logs for unusual application crashes or process behavior involving the Free Download Manager executable.

Compensating Controls: Restrict application execution privileges and ensure that users do not import download lists from untrusted or unverified sources.

Exploitation status

Public Exploit Available: Yes, a public exploit exists as documented in the Exploit Database (EDB-ID 44499).

Analyst recommendation

This vulnerability represents a critical risk to the integrity and security of host systems. Because a functional exploit is publicly available and the flaw allows for arbitrary code execution, it is imperative that organizations identify and remove the vulnerable version of Free Download Manager from all managed endpoints immediately.

More Free Download Manager CVEs

Sources

Originally found and disclosed by Marwan Shamel, per the CVE Program record.