CVE-2018-25260

HIGH

MAGIX Music Editor 3.1 Buffer Overflow via SEH

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25260. PoCs published by bzyo.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in MAGIX Music Editor 3.1 by overwriting the SEH handler and executing a calc.exe payload via a crafted text file loaded into the FreeDB Proxy Options field.

Description

MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload, paste it into the Server field via the CD menu's FreeDB Proxy Options, and trigger code execution when settings are accepted.

Exploits (1)

exploitdb WORKING POC
by bzyo · pythonlocalwindows_x86
https://www.exploit-db.com/exploits/46056

This exploit demonstrates a buffer overflow vulnerability in MAGIX Music Editor 3.1 by overwriting the SEH handler and executing a calc.exe payload via a crafted text file loaded into the FreeDB Proxy Options field.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MAGIX Music Editor 3.1
No auth needed
Prerequisites: MAGIX Music Editor 3.1 installed on Windows 7 SP1 x86 · User interaction to paste malicious content into the FreeDB Proxy Options field
devstral-2 · analyzed Apr 22, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: MAGIX Music Editor 3.1 Buffer Overflow via SEH
https://www.vulncheck.com/advisories/magix-music-editor-buffer-overflow-via-seh
Exploit exploit
ExploitDB-46056
https://www.exploit-db.com/exploits/46056
Product product
Official Product Homepage
https://www.magix.com/us/
Product product
Product Reference
https://www.magix.com/us/music/mp3-deluxe/

Scores

CVSS v3 8.4
EPSS 0.0021
EPSS Percentile 11.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
Magix/MAGIX Music Editor 3.1
magix/music_editor_deluxe < 3.1
Published Apr 22, 2026
Tracked Since Apr 22, 2026