CVE-2019-25631
8.4AIDA64 · AIDA64 Business
AIDA64 Business 5.99.4900 is vulnerable to a structured exception handling buffer overflow, allowing local attackers to execute arbitrary code via malicious shellcode injection.
Executive summary
A local buffer overflow vulnerability in AIDA64 Business 5.99.4900 allows unauthenticated local attackers to execute arbitrary code with application privileges.
Vulnerability
The application is susceptible to a structured exception handling (SEH) buffer overflow (CWE-787). An attacker can trigger this flaw by injecting crafted shellcode into the SMTP display name field or the report wizard functionality, which allows for the execution of arbitrary code with the privileges of the running application.
Business impact
Successful exploitation of this vulnerability permits a local attacker to gain full control over the application process, potentially leading to unauthorized access to sensitive system information or further local privilege escalation. Given the CVSS score of 8.4, this vulnerability represents a significant risk to the integrity and confidentiality of the host system.
Remediation
Immediate Action: Users should update to the latest version of AIDA64 Business to ensure all known security vulnerabilities are patched. If an update is not immediately feasible, restrict access to the application to trusted users only.
Proactive Monitoring: Security teams should monitor system logs for suspicious application crashes or unusual process activity originating from the AIDA64 executable.
Compensating Controls: Since this is a local attack vector, ensure that standard endpoint protection and host-based intrusion prevention systems are active to detect and block malicious code execution attempts.
Exploitation status
Public Exploit Available: Yes: A proof of concept exploit and technical write up are available via ExploitDB (EDB-ID: 46639).
Analyst recommendation
The presence of a functional proof of concept and the potential for arbitrary code execution elevate the urgency of this remediation. System administrators must prioritize updating the affected software to a version where this SEH buffer overflow is resolved to prevent potential compromise of the host environment.
Sources
Originally found and disclosed by Peyman Forouzan #, per the CVE Program record.
- ExploitDB-46639 Exploit / PoC
- Official Product Homepage
- Product Reference
- VulnCheck Advisory: AIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunter Third-party advisory