CVE-2019-25336

S

potAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system.

References
Configurations

Configuration 1 (hide)

cpe:2.3:a:nsasoft:spotauditor:5.3.2:*:*:*:*:*:*:*

History

20 Feb 2026, 21:10

Type Values Removed Values Added
First Time Nsasoft spotauditor
Nsasoft
CPE cpe:2.3:a:nsasoft:spotauditor:5.3.2:*:*:*:*:*:*:*
Summary
  • (es) SpotAuditor 5.3.2 contiene una vulnerabilidad local de desbordamiento de búfer en la herramienta Base64 Encrypted Password que permite a los atacantes ejecutar código arbitrario mediante la creación de una carga útil maliciosa. Los atacantes pueden generar una carga útil codificada en Base64 especialmente diseñada para desencadenar una sobrescritura del controlador de excepciones estructuradas (SEH) y ejecutar shellcode en el sistema vulnerable.
References () http://www.nsauditor.com/ - () http://www.nsauditor.com/ - Product
References () https://www.exploit-db.com/exploits/47719 - () https://www.exploit-db.com/exploits/47719 - Exploit, Third Party Advisory, VDB Entry
References () https://www.exploit-db.com/exploits/47759 - () https://www.exploit-db.com/exploits/47759 - Exploit, Third Party Advisory, VDB Entry
References () https://www.vulncheck.com/advisories/spotauditor-base-local-buffer-overflow-seh - () https://www.vulncheck.com/advisories/spotauditor-base-local-buffer-overflow-seh - Broken Link

13 Feb 2026, 14:23

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 23:16

Updated : 2026-02-20 21:10


NVD link : CVE-2019-25336

Mitre link : CVE-2019-25336

CVE.ORG link : CVE-2019-25336


JSON object : View

Products Affected
CWE
CWE-121

Stack-based Buffer Overflow