nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-25299 CVE-2018-25299
HIGH
Prime95 29.4b8 Local Buffer Overflow via SEH
Record summary
CVE-2018-25299 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and execute system commands.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 30, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Prime95Browse Mersenne / Prime95 | CVE List | 29.4b8 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBPrime95 29.4b8 - Stack Buffer Overflow (SEH)ExploitDB exploitby crash_manucootNot analyzed1 file
References
5ExploitDB-44649exploit
https://www.exploit-db.com/exploits/44649 Official Product Homepageproduct
https://www.mersenne.org/ Product Referenceproduct
https://www.mersenne.org/download VulnCheck Advisory: Prime95 29.4b8 Local Buffer Overflow via SEHThird-party advisory
https://www.vulncheck.com/advisories/prime95-29-4b8-local-buffer-overflow-via-seh