Record summary

CVE-2019-25634 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.

Description

Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input file that overflows a buffer, overwrites the SEH chain with a POP-POP-RET gadget address, and uses an egghunter payload to locate and execute shellcode for code execution.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.1.2affected

Proofs of concept

1

Catalogued exploits

ExploitDBBase64 Decoder 1.1.2 - Local Buffer Overflow (SEH Egghunter)ExploitDB exploitby Paolo PeregoNot analyzed1 file
ExploitDB

PoC details

References

5