CVE-2019-25360

CRITICAL

Aida64 Engineer 6.10.5200 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25360. PoCs published by daejinoh.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Aida64 6.10.5200 by overwriting the SEH (Structured Exception Handler) to achieve arbitrary code execution. The payload includes shellcode and leverages a POP POP RET gadget to bypass DEP.

Description

Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed payload. Attackers can exploit the vulnerability by creating a malformed log file with carefully constructed SEH (Structured Exception Handler) overwrite techniques to achieve remote code execution.

Exploits (1)

exploitdb WORKING POC
by daejinoh · pythonlocalwindows
https://www.exploit-db.com/exploits/47574

This exploit demonstrates a buffer overflow vulnerability in Aida64 6.10.5200 by overwriting the SEH (Structured Exception Handler) to achieve arbitrary code execution. The payload includes shellcode and leverages a POP POP RET gadget to bypass DEP.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: AIDA64 Engineer 6.10.5200
No auth needed
Prerequisites: Aida64 6.10.5200 installed on Windows 7 SP1 · User interaction to trigger the payload via logging preferences
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4
Core References
Various Sources product
https://www.aida64.com
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47574
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/aida-buffer-overflow

Scores

CVSS v3 9.8
EPSS 0.0067
EPSS Percentile 47.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-121
Status published
Products (2)
aida64/aida64 6.10.5200
FinalWire Ltd./Aida64 6.10.5200
Published Feb 18, 2026
Tracked Since Feb 19, 2026