CVE-2018-25378

MEDIUM

Notebook Pro 2.0 Denial of Service via Notebook Name Field

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25378. PoCs published by Ali Alipour.

AI-analyzed exploit summary This Python script generates a malicious payload to trigger a Denial of Service (DoS) in Notebook Pro 2.0 by overwriting a buffer with 500 'A' characters. The exploit creates a file named 'Notebook.txt' which, when pasted into the application's 'New Notebook Name' field, causes the software to crash.

Description

Notebook Pro 2.0 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string in the notebook name field. Attackers can create a malicious text file containing 500 or more characters, paste the content into the New Notebook Name field, and trigger an application crash when attempting to create and save the notebook.

Exploits (1)

exploitdb WORKING POC
by Ali Alipour · pythondoswindows_x86-64
https://www.exploit-db.com/exploits/45420

This Python script generates a malicious payload to trigger a Denial of Service (DoS) in Notebook Pro 2.0 by overwriting a buffer with 500 'A' characters. The exploit creates a file named 'Notebook.txt' which, when pasted into the application's 'New Notebook Name' field, causes the software to crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Notebook Pro 2.0
No auth needed
Prerequisites: Notebook Pro 2.0 installed on Windows 10 · ability to create a file and paste its contents into the application
devstral-2 · analyzed May 25, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-45420
https://www.exploit-db.com/exploits/45420
Third Party Advisory third-party-advisory
VulnCheck Advisory: Notebook Pro 2.0 Denial of Service via Notebook Name Field
https://www.vulncheck.com/advisories/notebook-pro-denial-of-service-via-notebook-name-field

Scores

CVSS v3 6.2
EPSS 0.0014
EPSS Percentile 3.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-789
Status published
Products (1)
Stokedonit/Notebook Pro 2.0
Published May 25, 2026
Tracked Since May 25, 2026