Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clicking the scale icon to execute shellcode with application privileges.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Admin-express
Admin-express admin-express |
|
| Vendors & Products |
Admin-express
Admin-express admin-express |
Sun, 22 Mar 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Admin Express 1.2.5.485 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an alphanumeric encoded payload in the Folder Path field. Attackers can trigger the vulnerability through the System Compare feature by pasting a crafted buffer overflow payload into the left-hand side Folder Path field and clicking the scale icon to execute shellcode with application privileges. | |
| Title | Admin Express 1.2.5.485 Local SEH Buffer Overflow via Folder Path | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-22T13:38:45.511Z
Updated: 2026-03-22T13:38:45.511Z
Reserved: 2026-03-22T13:21:59.416Z
Link: CVE-2019-25612
No data.
Status : Awaiting Analysis
Published: 2026-03-22T14:16:29.550
Modified: 2026-03-23T14:31:37.267
Link: CVE-2019-25612
No data.