
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2018-25344 is a stack-based buffer overflow vulnerability in 10-Strike Network Inventory Explorer version 8.54, specifically in the registration key input field. It allows local attackers to execute arbitrary code by triggering a Structured Exception Handler (SEH) overwrite. The vulnerability was formally published on May 23, 2026, and assigned by VulnCheck. It carries a CVSS v3.1 base score of 8.4 (High) and a CVSS v4.0 base score of 8.6 (High) (VulnCheck Advisory, Exploit-DB).
The root cause is a stack-based buffer overflow (CWE-121) in the registration key input field of 10-Strike Network Inventory Explorer 8.54. An attacker crafts a malicious registration key string consisting of 4,188 bytes of padding followed by SEH chain values and shellcode, then pastes it into the application's registration dialog. This overflows the stack buffer and overwrites the Structured Exception Handler chain, redirecting execution flow to attacker-controlled shellcode. No authentication or elevated privileges are required — only local access to the application's registration dialog (VulnCheck Advisory, Exploit-DB).
Successful exploitation allows a local attacker to execute arbitrary code with the privileges of the Network Inventory Explorer application process. This can result in full confidentiality, integrity, and availability compromise of the affected system at the application privilege level. While the attack vector is local and scope is unchanged, an attacker with local access could leverage code execution for privilege escalation or lateral movement within the network environment (VulnCheck Advisory).
A public proof-of-concept exploit has been available on Exploit-DB (EDB-44840) since 2018, predating the formal CVE assignment (Exploit-DB). Despite the PoC availability, there is no current evidence of active in-the-wild exploitation or threat actor attribution. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (VulnCheck Advisory).
cmd.exe, powershell.exe, network tools) following interaction with the registration dialog.NetworkInventoryExplorer.exe with exception codes related to access violations around the time of registration dialog use.No vendor patch has been confirmed as available for this vulnerability. As interim mitigations, restrict access to systems running 10-Strike Network Inventory Explorer 8.54 to trusted users only, and limit physical or remote access to those workstations. Implement input validation controls or application whitelisting to prevent execution of unexpected child processes from the application. Consider disabling or removing the registration dialog functionality if not operationally required, and monitor for anomalous process behavior associated with the application (VulnCheck Advisory).
The CVE received limited public attention at the time of the original Exploit-DB submission in 2018, and broader coverage emerged only after formal CVE assignment in May 2026. A technical write-up was published by Infinit Security detailing the SEH-based exploitation technique (Infinit Security). The vulnerability was also noted in CISA's weekly vulnerability bulletin for the week of May 18, 2026 (CISA Bulletin). No significant vendor statement or widespread community discussion has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."