CVE-2019-25475

MEDIUM

SQL Server Password Changer 1.90 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25475. PoCs published by Velayutham Selvaraj_ Praveen Thiyagarayam.

AI-analyzed exploit summary This exploit generates a large buffer of 'A' characters (6000 bytes) to trigger a denial-of-service (DoS) condition in SQL Server Password Changer v1.90 by overflowing a field input. The payload is written to a file (Evil.txt) and manually pasted into the application to cause a crash.

Description

SQL Server Password Changer 1.90 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized payload. Attackers can inject 6000 bytes of data into the User Name and Registration Code field to trigger a denial of service condition.

Exploits (1)

exploitdb WORKING POC
by Velayutham Selvaraj_ Praveen Thiyagarayam · pythondoswindows
https://www.exploit-db.com/exploits/47318

This exploit generates a large buffer of 'A' characters (6000 bytes) to trigger a denial-of-service (DoS) condition in SQL Server Password Changer v1.90 by overflowing a field input. The payload is written to a file (Evil.txt) and manually pasted into the application to cause a crash.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: SQL Server Password Changer v1.90
No auth needed
Prerequisites: Python to generate the payload · Manual interaction to paste the payload into the target application
devstral-2 · analyzed Mar 12, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/47318

Scores

CVSS v3 6.2
EPSS 0.0012
EPSS Percentile 2.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
Top-Password/SQL Server Password Changer Denial of Service Exploit 1.90
Published Mar 11, 2026
Tracked Since Mar 12, 2026