CVE-2019-25659

MEDIUM

ASPRunner Professional 6.0.766 Local Buffer Overflow DoS

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25659. PoCs published by Rafael Pedrero.

AI-analyzed exploit summary This Python script generates a buffer overflow payload (180 'A' characters) to trigger a local DoS in ASPRunner Professional v6.0.766 by pasting the payload into the 'Project name' field during project creation.

Description

ASPRunner Professional 6.0.766 contains a local buffer overflow vulnerability that allows attackers to cause a denial of service by supplying an excessively long project name. Attackers can paste 180 or more characters into the Project name field during project creation to trigger an application crash.

Exploits (1)

exploitdb WORKING POC
by Rafael Pedrero · pythondoswindows
https://www.exploit-db.com/exploits/46293

This Python script generates a buffer overflow payload (180 'A' characters) to trigger a local DoS in ASPRunner Professional v6.0.766 by pasting the payload into the 'Project name' field during project creation.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: ASPRunner Professional v6.0.766
No auth needed
Prerequisites: ASPRunner Professional v6.0.766 installed · local access to the application
devstral-2 · analyzed Apr 07, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-46293
https://www.exploit-db.com/exploits/46293
Product product
Official Product Homepage
http://www.xlinesoft.com/asprunnerpro
Third Party Advisory third-party-advisory
VulnCheck Advisory: ASPRunner Professional 6.0.766 Local Buffer Overflow DoS
https://www.vulncheck.com/advisories/asprunner-professional-local-buffer-overflow-dos

Scores

CVSS v3 6.2
EPSS 0.0015
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (1)
Xlinesoft/ASPRunner Professional 6.0.766
Published Apr 05, 2026
Tracked Since Apr 06, 2026