CVE-2019-25623

MEDIUM

Luminance Studio 2.17 Denial of Service via Malformed Input

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25623. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This PoC demonstrates a Denial of Service (DoS) vulnerability in Luminance Studio 2.17 by creating a malformed file with a buffer of 'A' characters. The exploit writes the payload to a file, which when opened by the target software, triggers the DoS condition.

Description

Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create a text file with arbitrary character sequences and trigger the application to process the input, causing the application to become unresponsive or terminate abnormally.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · pythondoswindows
https://www.exploit-db.com/exploits/46130

This PoC demonstrates a Denial of Service (DoS) vulnerability in Luminance Studio 2.17 by creating a malformed file with a buffer of 'A' characters. The exploit writes the payload to a file, which when opened by the target software, triggers the DoS condition.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Luminance Studio 2.17
No auth needed
Prerequisites: Luminance Studio 2.17 installed on the target system
devstral-2 · analyzed Mar 24, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46130
https://www.exploit-db.com/exploits/46130
Product product
Official Product Homepage
http://www.pixarra.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Luminance Studio 2.17 Denial of Service via Malformed Input
https://www.vulncheck.com/advisories/luminance-studio-denial-of-service-via-malformed-input

Scores

CVSS v3 6.2
EPSS 0.0019
EPSS Percentile 8.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-641
Status published
Products (2)
Pixarra/Luminance Studio 2.17
pixarra/luminance_studio 2.17
Published Mar 23, 2026
Tracked Since Mar 23, 2026