Aida64 is a system diagnostics and monitoring utility with a narrow product footprint but significant reach in the enterprise and enthusiast computing markets, where its kernel-level access for hardware interrogation creates a substantial attack surface. Vulnerabilities affecting the product skew toward serious outcomes, concentrating in memory-safety weakness classes such as out-of-bounds writes, stack-based buffer overflows, and improper initialization that reflect the low-level nature of system-information gathering. Defenders should treat Aida64 updates as a patching priority in environments where the tool is deployed; current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aida64 over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25360CRITICAL Aida64 Engineer 6.10.5200 contains a buffer overflow vulnerability in the CSV logging configuration that allows attackers to execute malicious code by crafting a specially designed | Feb 18, 2026 | 9.8 | 34 | NO | NO |
CVE-2019-25633HIGH AIDA64 Extreme 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input t | Mar 24, 2026 | 8.4 | 27 | NO | NO |
CVE-2019-25631HIGH AIDA64 Business 5.99.4900 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by overwriting SEH pointers w | Mar 24, 2026 | 8.4 | 27 | NO | NO |
CVE-2019-25629HIGH AIDA64 Extreme 5.99.4900 contains a structured exception handler buffer overflow vulnerability in the logging functionality that allows local attackers to execute arbitrary code by | Mar 24, 2026 | 8.4 | 27 | NO | NO |
CVE-2020-19513HIGH Buffer overflow in FinalWire Ltd AIDA64 Engineer 6.00.5100 allows attackers to execute arbitrary code by creating a crafted input that will overwrite the SEH handler. | Feb 19, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-37140MEDIUM Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functional | Feb 5, 2026 | 5.5 | 20 | NO | NO |
CVE-2019-7244HIGH An issue was discovered in kerneld.sys in AIDA64 before 5.99. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x80112084 and does not properly filter the Model Specific | Mar 25, 2020 | 7.2 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aida64.
Media articles that mention a CVE ID that affects a product developed by Aida64 — matched by CVE ID, not by vendor name.