CVE-2019-25631

8.4

AIDA64 · AIDA64 Business

AIDA64 Business 5.99.4900 is vulnerable to a structured exception handling buffer overflow, allowing local attackers to execute arbitrary code via malicious shellcode injection.

Executive summary

A local buffer overflow vulnerability in AIDA64 Business 5.99.4900 allows unauthenticated local attackers to execute arbitrary code with application privileges.

Vulnerability

The application is susceptible to a structured exception handling (SEH) buffer overflow (CWE-787). An attacker can trigger this flaw by injecting crafted shellcode into the SMTP display name field or the report wizard functionality, which allows for the execution of arbitrary code with the privileges of the running application.

Business impact

Successful exploitation of this vulnerability permits a local attacker to gain full control over the application process, potentially leading to unauthorized access to sensitive system information or further local privilege escalation. Given the CVSS score of 8.4, this vulnerability represents a significant risk to the integrity and confidentiality of the host system.

Remediation

Immediate Action: Users should update to the latest version of AIDA64 Business to ensure all known security vulnerabilities are patched. If an update is not immediately feasible, restrict access to the application to trusted users only.

Proactive Monitoring: Security teams should monitor system logs for suspicious application crashes or unusual process activity originating from the AIDA64 executable.

Compensating Controls: Since this is a local attack vector, ensure that standard endpoint protection and host-based intrusion prevention systems are active to detect and block malicious code execution attempts.

Exploitation status

Public Exploit Available: Yes: A proof of concept exploit and technical write up are available via ExploitDB (EDB-ID: 46639).

Analyst recommendation

The presence of a functional proof of concept and the potential for arbitrary code execution elevate the urgency of this remediation. System administrators must prioritize updating the affected software to a version where this SEH buffer overflow is resolved to prevent potential compromise of the host environment.

Sources

Originally found and disclosed by Peyman Forouzan #, per the CVE Program record.