AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. Attackers can inject egg hunter shellcode through the SMTP display name field in preferences or report wizard functionality to trigger the overflow and execute code with application privileges.
References
| Link | Resource |
|---|---|
| https://www.aida64.com | Product |
| https://www.aida64.com/downloads | Product |
| https://www.exploit-db.com/exploits/46639 | Exploit Third Party Advisory VDB Entry |
| https://www.vulncheck.com/advisories/aida64-business-seh-buffer-overflow-via-egghunter | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-24 12:16
Updated : 2026-03-27 16:59
NVD link : CVE-2019-25631
Mitre link : CVE-2019-25631
CVE.ORG link : CVE-2019-25631
JSON object : View
Products Affected
aida64
- aida64
CWE
CWE-787
Out-of-bounds Write
