CVE-2018-25263

HIGH

Faleemi Desktop Software 1.8.2 Local Buffer Overflow SEH

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25263. PoCs published by Gionathan Reale.

AI-analyzed exploit summary This exploit leverages a local buffer overflow vulnerability in Faleemi Desktop Software 1.8.2 via the 'Device alias' field, using a SEH-based exploit to achieve arbitrary code execution (spawning a calculator). The payload includes a crafted buffer, NSEH/SEH overwrite, NOP sled, and shellcode generated by msfvenom.

Description

Faleemi Desktop Software 1.8.2 contains a local buffer overflow vulnerability in the Device alias field that allows local attackers to trigger a structured exception handler (SEH) overwrite. Attackers can craft a malicious payload and paste it into the Device alias field within the Managing Log interface to execute arbitrary code with calculator proof-of-concept execution.

Exploits (1)

exploitdb WORKING POC
by Gionathan Reale · pythonlocalwindows_x86
https://www.exploit-db.com/exploits/45492

This exploit leverages a local buffer overflow vulnerability in Faleemi Desktop Software 1.8.2 via the 'Device alias' field, using a SEH-based exploit to achieve arbitrary code execution (spawning a calculator). The payload includes a crafted buffer, NSEH/SEH overwrite, NOP sled, and shellcode generated by msfvenom.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Faleemi Desktop Software 1.8.2
No auth needed
Prerequisites: Victim must open the exploit file and paste its contents into the 'Device alias' field in the application
devstral-2 · analyzed Apr 26, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory third-party-advisory
VulnCheck Advisory: Faleemi Desktop Software 1.8.2 Local Buffer Overflow SEH
https://www.vulncheck.com/advisories/faleemi-desktop-software-local-buffer-overflow-seh
Exploit exploit
ExploitDB-45492
https://www.exploit-db.com/exploits/45492
Product product
Product Reference
http://support.faleemi.com/fsc776/Faleemi_v1.8.exe

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 4.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
faleemi/Faleemi Desktop Software 1.8.2
Published Apr 26, 2026
Tracked Since Apr 26, 2026