Record summary

CVE-2018-25299 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.

Description

Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and execute system commands.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List29.4b8affected

Proofs of concept

1

Catalogued exploits

ExploitDBPrime95 29.4b8 - Stack Buffer Overflow (SEH)ExploitDB exploitby crash_manucootNot analyzed1 file
ExploitDB

PoC details

References

5