nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25631 CVE-2019-25631
HIGH
AIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunter
Record summary
CVE-2019-25631 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.
Description
AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. Attackers can inject egg hunter shellcode through the SMTP display name field in preferences or report wizard functionality to trigger the overflow and execute code with application privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AIDA64 BusinessBrowse Aida64 / AIDA64 Business | CVE List | 5.99.4900 # | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAIDA64 Business 5.99.4900 - SEH Buffer Overflow (EggHunter)ExploitDB exploitby Peyman ForouzanNot analyzed1 file
References
5Official Product Homepageproduct
https://www.aida64.com/ Product Referenceproduct
https://www.aida64.com/downloads ExploitDB-46639exploit
https://www.exploit-db.com/exploits/46639 VulnCheck Advisory: AIDA64 Business 5.99.4900 SEH Buffer Overflow via EggHunterThird-party advisory
https://www.vulncheck.com/advisories/aida64-business-seh-buffer-overflow-via-egghunter