CVE-2018-25376

HIGH

Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25376. PoCs published by Shubham Singh.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Socusoft 3GP Photo Slideshow 8.05, leveraging SEH overwrite to execute a reverse shell payload. The exploit constructs a malicious input file that triggers the overflow when pasted into the registration fields.

Description

Socusoft 3GP Photo Slideshow 8.05 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft malicious input in the Registration Name and Registration Key fields to overwrite the SEH chain and execute shellcode for reverse shell access.

Exploits (1)

exploitdb WORKING POC
by Shubham Singh · pythonlocalwindows_x86
https://www.exploit-db.com/exploits/45352

This exploit demonstrates a buffer overflow vulnerability in Socusoft 3GP Photo Slideshow 8.05, leveraging SEH overwrite to execute a reverse shell payload. The exploit constructs a malicious input file that triggers the overflow when pasted into the registration fields.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Socusoft 3GP Photo Slideshow 8.05
No auth needed
Prerequisites: Python environment · msfvenom for payload generation · network connectivity for reverse shell
devstral-2 · analyzed May 25, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-45352
https://www.exploit-db.com/exploits/45352
Third Party Advisory third-party-advisory
VulnCheck Advisory: Socusoft 3GP Photo Slideshow 8.05 Buffer Overflow SEH
https://www.vulncheck.com/advisories/socusoft-3gp-photo-slideshow-buffer-overflow-seh

Scores

CVSS v3 8.4
EPSS 0.0018
EPSS Percentile 7.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
SocuSoft/3GP Photo Slideshow 8.05
Published May 25, 2026
Tracked Since May 25, 2026