CVE-2019-25679

7.8

Serial · RealTerm Serial Terminal

RealTerm Serial Terminal 2.0.0.70 contains a local structured exception handling (SEH) buffer overflow vulnerability in the Echo Port tab that allows arbitrary code execution via a malicious payload.

Executive summary

A local buffer overflow vulnerability in RealTerm Serial Terminal 2.0.0.70 allows attackers to achieve arbitrary code execution on the host system.

Vulnerability

This vulnerability is a structured exception handling (SEH) buffer overflow (CWE-787) occurring within the Echo Port tab. An attacker can trigger the flaw by pasting a crafted malicious payload into the Port field and clicking the Change button, allowing for arbitrary code execution.

Business impact

The exploitation of this vulnerability results in full system compromise for the affected user, as it allows for the execution of arbitrary code with the privileges of the application. Given the CVSS score of 7.8, this represents a high risk to organizational security, as it could lead to unauthorized data access, the installation of persistent backdoors, or the lateral movement of an attacker within the local environment.

Remediation

Immediate Action: Users should discontinue the use of version 2.0.0.70 and upgrade to a patched version of the software if available, or replace the utility with a secure alternative.

Proactive Monitoring: Security teams should monitor system access logs for suspicious process execution or unexpected application crashes involving realterm.exe that may indicate exploitation attempts.

Compensating Controls: Since this is a local attack vector, enforce strict access controls on the host machine to ensure that only authorized personnel can execute the application.

Exploitation status

Public Exploit Available: Yes, a published exploit exists and is documented in the Exploit Database (EDB-ID 46441).

Analyst recommendation

This vulnerability presents a significant risk due to the availability of functional exploit code. Organizations using RealTerm 2.0.0.70 must prioritize the immediate migration to a secure version or remove the software from the environment to eliminate the risk of local code execution.

Sources

Originally found and disclosed by Matteo Malvica, per the CVE Program record.