CVE-2018-25255 describes a local buffer overflow vulnerability in 10-Strike LANState 8.8's structured exception handling. This flaw allows local attackers to execute arbitrary code by crafting a malicious LSM map file that, when opened, overflows a buffer and overwrites the SEH chain. The vulnerability carries a CVSSv3.1 score of 8.4 HIGH, indicating a severe impact on confidentiality, integrity, and availability, with low attack complexity. While the CVSS vector indicates no user interaction (UI:N), the description implies exploitation occurs when a local user opens the specially crafted file. There is no evidence of active exploitation, nor are public exploit modules or significant community discussion available for this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| 10-Strike | Strike LANState | 8.8CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.