CVE-2018-25267 is a local buffer overflow vulnerability affecting UltraISO version 9.7.1.3519 in the Make CD/DVD Image dialog. The flaw exists in the Output FileName field, where attackers can craft a malicious filename string to overwrite Structured Exception Handling (SEH) and SE handler records, potentially leading to application crashes. The vulnerability has a CVSS score of 6.2 (Medium severity) with a local attack vector requiring no privileges or user interaction. While the attack complexity is low, the impact is limited to availability, with no confidentiality or integrity compromise possible. This indicates a denial of service risk rather than a critical system compromise. There is currently no evidence of active exploitation, with an EPSS score of 0.00012 indicating minimal real-world exploitation likelihood. The vulnerability is not listed on the CISA KEV catalog and remains inactive on security hot lists, suggesting limited community attention and low practical threat to operational environments at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.7.1.3519CPE matchmatch criteria | cpe:2.3:a:ezbsystems:ultraiso:9.7.1.3519:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.