Vulnerability Description
Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh value and seh pointer to trigger the overflow when adding a new user account.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://www.exploit-db.com/exploits/47411
- https://www.vulncheck.com/advisories/easy-file-sharing-web-server-local-seh-over
FAQ
What is CVE-2019-25466?
CVE-2019-25466 is a vulnerability with a CVSS score of 8.4 (HIGH). Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. At...
How severe is CVE-2019-25466?
CVE-2019-25466 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-25466?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.