CVE-2019-25435: Sricam DeviceViewer 3.12.0.1 Local Buffer Overflow DEP Bypass
Sricam DeviceViewer 3.12.0.1 contains a local buffer overflow vulnerability in the user management add user function that allows authenticated attackers to execute arbitrary code by bypassing data execution prevention. Attackers can inject a malicious payload through the Username field in User Management to trigger a stack-based buffer overflow and execute commands via ROP chain gadgets.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25435?
CVE-2019-25435 is considered to have a high severity due to its potential for arbitrary code execution.
How do I fix CVE-2019-25435?
To fix CVE-2019-25435, update to the latest version of Sricam DeviceViewer that addresses this vulnerability.
What type of vulnerability is CVE-2019-25435?
CVE-2019-25435 is a local buffer overflow vulnerability that can lead to arbitrary code execution.
Who is affected by CVE-2019-25435?
Users of Sricam DeviceViewer version 3.12.0.1 are affected by CVE-2019-25435.
What are the potential impacts of exploiting CVE-2019-25435?
Exploiting CVE-2019-25435 could allow authenticated attackers to execute arbitrary code on the affected system.