CVE-2019-25360 describes a critical buffer overflow vulnerability in Aida64 Engineer version 6.10.5200, specifically within its CSV logging configuration. This flaw allows unauthenticated remote attackers to achieve remote code execution by crafting a specially designed, malformed log file that leverages Structured Exception Handler (SEH) overwrite techniques. With a CVSS score of 9.8 (Critical), successful exploitation grants full control over the affected system, impacting confidentiality, integrity, and availability. While there are no known public exploits or evidence of active exploitation in the wild, the vulnerability has garnered some community discussion, including mentions on GitHub.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.10.5200CPE matchmatch criteria | cpe:2.3:a:aida64:aida64:6.10.5200:*:*:*:engineer:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.