Official Product Homepageproduct
http://www.flexhex.com/ CVE-2019-25627
HIGH
FlexHEX 2.71 Local Buffer Overflow via SEH Unicode
Record summary
CVE-2019-25627 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
FlexHEXBrowse Flexhex / FlexHEX | CVE List | 2.71 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBFlexHEX 2.71 - SEH Buffer Overflow (Unicode)ExploitDB exploitby Chris AuNot analyzed1 file
References
5Product Referenceproduct
http://www.flexhex.com/download/flexhex_setup.exe nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25627 ExploitDB-46665exploit
https://www.exploit-db.com/exploits/46665 VulnCheck Advisory: FlexHEX 2.71 Local Buffer Overflow via SEH UnicodeThird-party advisory
https://www.vulncheck.com/advisories/flexhex-local-buffer-overflow-via-seh-unicode