CVE-2019-25666

MEDIUM

SpotAuditor 3.6.7 Denial of Service Buffer Overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25666. PoCs published by Rafael Pedrero.

AI-analyzed exploit summary This Python script generates a buffer overflow payload to trigger a Denial of Service (DoS) in SpotAuditor v3.6.7 by exploiting a local buffer overflow vulnerability in the Base64 Password Decoder tool. The exploit creates a file with 2000 'A' characters, which when pasted into the tool and decrypted, causes the application to crash.

Description

SpotAuditor 3.6.7 contains a local buffer overflow vulnerability in the Base64 Password Decoder component that allows attackers to crash the application. Attackers can supply an oversized Base64 string through the decoder interface to trigger a denial of service condition.

Exploits (1)

exploitdb WORKING POC
by Rafael Pedrero · pythondoswindows
https://www.exploit-db.com/exploits/46313

This Python script generates a buffer overflow payload to trigger a Denial of Service (DoS) in SpotAuditor v3.6.7 by exploiting a local buffer overflow vulnerability in the Base64 Password Decoder tool. The exploit creates a file with 2000 'A' characters, which when pasted into the tool and decrypted, causes the application to crash.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: SpotAuditor v3.6.7
No auth needed
Prerequisites: SpotAuditor v3.6.7 installed on Windows XP SP3 · Access to the Base64 Password Decoder tool within the application
devstral-2 · analyzed Apr 07, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-46313
https://www.exploit-db.com/exploits/46313
Product product
Official Product Homepage
http://www.nsauditor.com/order.html
Third Party Advisory third-party-advisory
VulnCheck Advisory: SpotAuditor 3.6.7 Denial of Service Buffer Overflow
https://www.vulncheck.com/advisories/spotauditor-denial-of-service-buffer-overflow

Scores

CVSS v3 6.2
EPSS 0.0024
EPSS Percentile 14.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-787
Status published
Products (2)
nsasoft/spotauditor < 3.6.7
Nsauditor/SpotAuditor 3.6.7
Published Apr 05, 2026
Tracked Since Apr 06, 2026