
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25360 is a stack-based buffer overflow vulnerability in AIDA64 Engineer version 6.10.5200, affecting the application's CSV logging configuration. Attackers can exploit this flaw by crafting a malformed CSV log file using Structured Exception Handler (SEH) overwrite techniques to achieve code execution. The vulnerability was published on February 18, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Feedly).
The root cause is a stack-based buffer overflow (CWE-121) in AIDA64 Engineer 6.10.5200's CSV logging configuration handler. An attacker crafts a specially malformed log file that overflows a stack buffer, enabling overwrite of the Structured Exception Handler (SEH) chain — a classic Windows exploitation technique used to redirect execution flow. Exploitation requires the victim to open or process the malicious CSV log file within the application. A public exploit is available on Exploit-DB (EDB-47574) demonstrating the SEH overwrite technique (Exploit-DB, Feedly).
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running AIDA64 Engineer, potentially resulting in complete system compromise. This includes unauthorized access to sensitive data (high confidentiality impact), unauthorized modification of system files and configurations (high integrity impact), and denial of service (high availability impact). The scope is limited to the affected host, but privilege escalation or lateral movement may be possible depending on the user's access level (Feedly).
A public proof-of-concept exploit (EDB-47574) is available on Exploit-DB, demonstrating the SEH overwrite technique against AIDA64 Engineer 6.10.5200 (Exploit-DB). Despite the PoC's availability, there is no confirmed evidence of active in-the-wild exploitation or threat actor attribution at this time. The EPSS score is approximately 0.235%, indicating a low current probability of exploitation in the wild. This CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
cmd.exe, powershell.exe, mshta.exe); AIDA64 process crashing or generating Windows Error Reporting (WER) crash dumps.aida64.exe; SEH-related exception records in crash dumps.No official patch information is currently available from the vendor for this specific vulnerability. Organizations should apply any available updates from FinalWire (AIDA64's developer) and monitor for newer versions that address this issue. As interim mitigations: restrict the ability to import or process CSV log files from untrusted sources; disable CSV logging functionality if not operationally required; apply the principle of least privilege to accounts running AIDA64 Engineer; and monitor AIDA64 process activity for anomalous child process spawning or network connections (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."