CVE-2018-25299
Last modified
CVE-2018-25299 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and execute system commands.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Prime95 29.4b8 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by exploiting structured exception handling (SEH) mechanisms. Attackers can inject malicious payload through the optional proxy hostname field in the PrimeNet connection settings to trigger the overflow and execute system commands.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Mersenne | Prime95 | 29.4b8 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2018-25299?
How severe is CVE-2018-25299?
How do I fix CVE-2018-25299?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-25293Prime95 29.4b7 contains a buffer overflow vulnerability in t…6.9
- CVE-2018-25294CEWE Photoshow 6.3.4 contains a buffer overflow vulnerabilit…8.7
- CVE-2018-25295ObserverIP Scan Tool 1.4.0.1 contains a denial of service vu…6.9
- CVE-2018-25296P10 Central Management Software 1.4.13 contains a buffer ove…6.8
- CVE-2018-25297Wansview 1.0.2 contains a buffer overflow vulnerability that…6.9
- CVE-2018-25298Merge PACS 7.0 contains a cross-site request forgery vulnera…6.9
- CVE-2018-25300XATABoost CMS 1.0.0 contains a union-based SQL injection vul…8.8
- CVE-2018-25301Easy MPEG to DVD Burner 1.7.11 contains a structured excepti…8.6
- CVE-2018-25302Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a stru…8.5
- CVE-2018-25303Allok Video to DVD Burner 2.6.1217 contains a stack-based bu…8.6
- CVE-2018-25304Free Download Manager 2.0 Build 417 contains a local buffer …8.6
- CVE-2018-25305librsvg2-bin 2.40.13 contains a buffer overflow vulnerabilit…6.9
Are you affected by CVE-2018-25299?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
