CVE-2019-25360
FinalWire AIDA64 vulnerability analysis and mitigation

Overview

CVE-2019-25360 is a stack-based buffer overflow vulnerability in AIDA64 Engineer version 6.10.5200, affecting the application's CSV logging configuration. Attackers can exploit this flaw by crafting a malformed CSV log file using Structured Exception Handler (SEH) overwrite techniques to achieve code execution. The vulnerability was published on February 18, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly).

Technical details

The root cause is a stack-based buffer overflow (CWE-121) in AIDA64 Engineer 6.10.5200's CSV logging configuration handler. An attacker crafts a specially malformed log file that overflows a stack buffer, enabling overwrite of the Structured Exception Handler (SEH) chain — a classic Windows exploitation technique used to redirect execution flow. Exploitation requires the victim to open or process the malicious CSV log file within the application. A public exploit is available on Exploit-DB (EDB-47574) demonstrating the SEH overwrite technique (Exploit-DB, Feedly).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running AIDA64 Engineer, potentially resulting in complete system compromise. This includes unauthorized access to sensitive data (high confidentiality impact), unauthorized modification of system files and configurations (high integrity impact), and denial of service (high availability impact). The scope is limited to the affected host, but privilege escalation or lateral movement may be possible depending on the user's access level (Feedly).

Exploitability

A public proof-of-concept exploit (EDB-47574) is available on Exploit-DB, demonstrating the SEH overwrite technique against AIDA64 Engineer 6.10.5200 (Exploit-DB). Despite the PoC's availability, there is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.235%, indicating a low current probability of exploitation in the wild. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify systems running AIDA64 Engineer 6.10.5200, which is commonly used by IT professionals and system administrators for hardware diagnostics and benchmarking.
  2. Craft malicious CSV file: Create a specially malformed CSV log file with an oversized or carefully structured payload designed to overflow the stack buffer in the CSV logging configuration handler.
  3. Embed SEH overwrite payload: Construct the payload to overwrite the Structured Exception Handler (SEH) chain on the stack, redirecting execution to attacker-controlled shellcode. Reference EDB-47574 for the specific payload structure (Exploit-DB).
  4. Deliver the file: Deliver the malicious CSV file to the target via social engineering, phishing, shared network drives, or by placing it in a directory that AIDA64 is configured to read.
  5. Trigger the vulnerability: Induce the victim to open or import the malicious CSV log file within AIDA64 Engineer, triggering the buffer overflow and SEH overwrite.
  6. Achieve code execution: The overwritten SEH handler redirects execution to the attacker's shellcode, enabling arbitrary command execution with the privileges of the AIDA64 process.

Indicators of compromise

  • File System: Unexpected or unfamiliar CSV files in AIDA64 log directories or user-accessible locations; presence of exploit files matching EDB-47574 patterns.
  • Process: Unusual child processes spawned by the AIDA64 Engineer process (e.g., cmd.exe, powershell.exe, mshta.exe); AIDA64 process crashing or generating Windows Error Reporting (WER) crash dumps.
  • Logs: Windows Event Log entries (Event ID 1000/1001) indicating application crashes or faults in aida64.exe; SEH-related exception records in crash dumps.
  • Network: Unexpected outbound network connections originating from the AIDA64 process to unknown external IP addresses (indicative of reverse shell or C2 activity).

Mitigation and workarounds

No official patch information is currently available from the vendor for this specific vulnerability. Organizations should apply any available updates from FinalWire (AIDA64's developer) and monitor for newer versions that address this issue. As interim mitigations: restrict the ability to import or process CSV log files from untrusted sources; disable CSV logging functionality if not operationally required; apply the principle of least privilege to accounts running AIDA64 Engineer; and monitor AIDA64 process activity for anomalous child process spawning or network connections (Feedly).

Additional resources


SourceThis report was generated using AI

Related FinalWire AIDA64 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-25633HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25631HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25629HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25360HIGH8.4
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 18, 2026
CVE-2020-37140MEDIUM4.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management