CVE-2019-25631
FinalWire AIDA64 vulnerability analysis and mitigation

Overview

CVE-2019-25631 is a structured exception handling (SEH) buffer overflow vulnerability in AIDA64 Business version 5.99.4900 that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. The vulnerability was originally discovered in 2019 and formally assigned a CVE identifier with public disclosure occurring in March 2026. It affects only AIDA64 Business 5.99.4900; other editions or versions are not confirmed as affected. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.6 (High) (Feedly, VulnCheck).

Technical details

The root cause is an out-of-bounds write (CWE-787) triggered by insufficient input validation in the SMTP display name field within the application's preferences or report wizard functionality. An attacker with local access can supply an overly long string in this field, causing a stack-based buffer overflow that overwrites the structured exception handler (SEH) chain pointers. By crafting the overflow payload to include egg hunter shellcode, the attacker can redirect execution flow to arbitrary shellcode placed elsewhere in memory. A public proof-of-concept exploit is listed on Exploit-DB (EDB-46639) (Exploit-DB, VulnCheck).

Impact

Successful exploitation allows a low-privileged local user to execute arbitrary code with the privileges of the AIDA64 Business application process, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive diagnostic data collected by AIDA64, modify application output or configuration, or crash the application. Because exploitation requires local access and does not escape the application's privilege context, lateral movement potential is limited, though it could serve as a privilege escalation step in a broader attack chain (Feedly, VulnCheck).

Exploitability

A proof-of-concept exploit is publicly available on Exploit-DB (EDB-46639), though automated analysis has not confirmed it as a fully weaponized exploit. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), reflecting very low probability of exploitation in the near term (Exploit-DB, Feedly).

Exploitation steps

  1. Reconnaissance: Confirm the target system is running AIDA64 Business version 5.99.4900 and that local user access is available.
  2. Access the vulnerable field: Open AIDA64 Business and navigate to the Preferences menu or the Report Wizard, then locate the SMTP display name input field.
  3. Craft the overflow payload: Construct a buffer overflow payload consisting of a large string (sufficient to overwrite the SEH chain on the stack), including a nSEH jump instruction and an SEH handler pointer redirected to a POP POP RET gadget within a loaded module.
  4. Embed egg hunter shellcode: Prepend or append egg hunter shellcode to the payload so that after SEH hijacking, the egg hunter searches process memory for the tagged final-stage shellcode.
  5. Inject the payload: Enter the crafted string into the SMTP display name field and trigger the overflow (e.g., by saving preferences or generating a report).
  6. Achieve code execution: The SEH overwrite redirects execution to the egg hunter, which locates and executes the final shellcode with AIDA64 application privileges (Exploit-DB, VulnCheck).

Indicators of compromise

  • Process: Unexpected child processes spawned by the AIDA64 Business process (e.g., cmd.exe, powershell.exe, or network utilities) following interaction with the preferences or report wizard UI.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing AIDA64 Business process faults around the time of exploitation attempts.
  • File System: Presence of shellcode-related artifacts or newly created executables in directories writable by the AIDA64 process user account.
  • Memory: Evidence of egg hunter shellcode patterns (e.g., repeated SCASD instructions or egg tag markers such as w00tw00t) in process memory dumps of the AIDA64 Business process.

Mitigation and workarounds

The patch status for AIDA64 Business is currently unknown; users should check the official AIDA64 downloads page for an updated version that addresses this vulnerability. As interim mitigations, restrict local access to systems running AIDA64 Business to trusted users only, and apply the principle of least privilege to limit the impact of any exploitation. Implement input validation controls where possible and monitor the SMTP display name and report wizard fields for anomalously long inputs. Organizations should also consider disabling or restricting the SMTP notification functionality if it is not required (AIDA64 Downloads, VulnCheck).

Community reactions

The vulnerability received limited industry attention, with automated CVE alert services such as RedPacketSecurity distributing notifications via social media (Mastodon) shortly after public disclosure in March 2026. No significant vendor statement from FinalWire (AIDA64's developer) has been identified, and no major security researchers have published detailed commentary or analysis beyond the original Exploit-DB submission and VulnCheck advisory (RedPacketSecurity, VulnCheck).

Additional resources


SourceThis report was generated using AI

Related FinalWire AIDA64 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-25633HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25631HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25629HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25360HIGH8.4
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 18, 2026
CVE-2020-37140MEDIUM4.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management