CVE-2019-25633

8.4

FinalWire · AIDA64 Extreme

AIDA64 Extreme 5.99.4900 is vulnerable to a structured exception handling (SEH) buffer overflow, allowing local attackers to execute arbitrary code via malicious input in specific UI interfaces.

Executive summary

A structured exception handling buffer overflow in AIDA64 Extreme 5.99.4900 allows a local attacker to achieve arbitrary code execution with application privileges.

Vulnerability

The application is susceptible to a buffer overflow (CWE-787) in the email preferences and report wizard interfaces. An attacker can supply a crafted payload within the Display name field or Load from file parameter to trigger an SEH overwrite, leading to arbitrary code execution by an unauthenticated local user.

Business impact

Successful exploitation of this vulnerability grants an attacker the ability to execute arbitrary code with the same privileges as the AIDA64 process. This could lead to full system compromise, the installation of persistent backdoors, or the exfiltration of sensitive system information. Given the CVSS 4.0 score of 8.4, this vulnerability represents a high risk to organizational security, particularly on workstations where AIDA64 is deployed.

Remediation

Immediate Action: Update AIDA64 Extreme to the latest available version provided by FinalWire, as version 5.99.4900 is confirmed vulnerable.

Proactive Monitoring: Monitor local system logs for unusual process execution patterns or crash reports associated with AIDA64 that may indicate exploitation attempts.

Compensating Controls: Restrict local user permissions to prevent unauthorized execution of administrative diagnostic tools and maintain strict endpoint security policies to mitigate local attack vectors.

Exploitation status

Public Exploit Available: Yes, a functional local exploit exists as documented by the Exploit Database (EDB-ID 46636).

Analyst recommendation

Organizations should treat this vulnerability with high priority despite the requirement for local access. System administrators must ensure that all instances of AIDA64 are updated to a patched version to eliminate the risk of arbitrary code execution. If patching is not immediately feasible, consider restricting the application to authorized administrative accounts only to minimize the potential attack surface.

Sources

Originally found and disclosed by Peyman Forouzan #, per the CVE Program record.