CVE-2019-25736

HIGH

LabF nfsAxe 3.7 Ping Client Buffer Overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25736. PoCs published by Dino Covotsos.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in LabF nfsAxe 3.7 Ping Client. It crafts a malicious payload with a JMP ESP address and shellcode to spawn calc.exe, exploiting the lack of input validation in the 'Host IP' field.

Description

LabF nfsAxe 3.7 Ping Client contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the Host IP field. Attackers can craft a specially formatted input file with shellcode and overwrite the return address to execute calc.exe or other arbitrary commands.

Exploits (1)

exploitdb WORKING POC
by Dino Covotsos · pythonlocalwindows
https://www.exploit-db.com/exploits/46737

This exploit demonstrates a buffer overflow vulnerability in LabF nfsAxe 3.7 Ping Client. It crafts a malicious payload with a JMP ESP address and shellcode to spawn calc.exe, exploiting the lack of input validation in the 'Host IP' field.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: LabF nfsAxe 3.7
No auth needed
Prerequisites: Windows XP SP3 ENG x86 · LabF nfsAxe 3.7 installed
devstral-2 · analyzed Jun 04, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-46737
https://www.exploit-db.com/exploits/46737
Product product
Official Product Homepage
http://www.labf.com/nfsaxe
Third Party Advisory third-party-advisory
VulnCheck Advisory: LabF nfsAxe 3.7 Ping Client Buffer Overflow
https://www.vulncheck.com/advisories/labf-nfsaxe-ping-client-buffer-overflow

Scores

CVSS v3 8.4
EPSS 0.0015
EPSS Percentile 4.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
Labf/LabF nfsAxe 3.7
Published Jun 04, 2026
Tracked Since Jun 04, 2026