CVE-2019-25566

MEDIUM

TransMac 12.3 Denial of Service via Volume Name Field

Title source: cna
STIX 2.1

Description

TransMac 12.3 contains a buffer overflow vulnerability in the volume name field that allows local attackers to crash the application by supplying an excessively long string. Attackers can create a malicious file with 1000 repeated characters, paste the content into the volume name field during disk image creation, and trigger an application crash.

Exploits (1)

exploitdb WORKING POC
by Alejandra Sánchez · pythondoswindows
https://www.exploit-db.com/exploits/46470

Scores

CVSS v3 6.2
EPSS 0.0002
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
acutesystems/transmac 12.3
Acutesystems/TransMac 12.3
Published Mar 21, 2026
Tracked Since Mar 21, 2026