CVE-2019-25327
CRITICALPrime95 29.8 build 6 - Remote Code Execution via User ID Input Field
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25327. PoCs published by stresser.
AI-analyzed exploit summary This exploit leverages a buffer overflow vulnerability in Prime95 29.8 build 6 via SEH overwrite, delivering a bind shell payload on port 3110. The PoC generates an 'Evil.txt' file containing the malicious input for manual pasting into the application.
Description
Prime95 version 29.8 build 6 contains a buffer overflow vulnerability in the user ID input field that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload and paste it into the PrimeNet user ID and proxy host fields to trigger a bind shell on port 3110.
Exploits (1)
This exploit leverages a buffer overflow vulnerability in Prime95 29.8 build 6 via SEH overwrite, delivering a bind shell payload on port 3110. The PoC generates an 'Evil.txt' file containing the malicious input for manual pasting into the application.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H