Record summary

CVE-2019-25627 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.

Description

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.71affected

Proofs of concept

1

Catalogued exploits

ExploitDBFlexHEX 2.71 - SEH Buffer Overflow (Unicode)ExploitDB exploitby Chris AuNot analyzed1 file
ExploitDB

PoC details

References

5