CVE-2018-25219 is a high-severity structured exception handling buffer overflow vulnerability affecting PassFab Excel Password Recovery 8.3.1. This allows a local attacker to achieve arbitrary code execution by supplying a crafted malicious payload in the registration code field during the registration process, resulting in a CVSS score of 8.4 (HIGH) due to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation (not in KEV), no public exploit code (Metasploit, ExploitDB), and minimal community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 8.3.1CPE matchmatch criteria | cpe:2.3:a:passfab:excel_password_recovery:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.