
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25631 is a structured exception handling (SEH) buffer overflow vulnerability in AIDA64 Business version 5.99.4900 that allows local attackers to execute arbitrary code by overwriting SEH pointers with malicious shellcode. The vulnerability was originally discovered in 2019 and formally assigned a CVE identifier with public disclosure occurring in March 2026. It affects only AIDA64 Business 5.99.4900; other editions or versions are not confirmed as affected. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.6 (High) (Feedly, VulnCheck).
The root cause is an out-of-bounds write (CWE-787) triggered by insufficient input validation in the SMTP display name field within the application's preferences or report wizard functionality. An attacker with local access can supply an overly long string in this field, causing a stack-based buffer overflow that overwrites the structured exception handler (SEH) chain pointers. By crafting the overflow payload to include egg hunter shellcode, the attacker can redirect execution flow to arbitrary shellcode placed elsewhere in memory. A public proof-of-concept exploit is listed on Exploit-DB (EDB-46639) (Exploit-DB, VulnCheck).
Successful exploitation allows a low-privileged local user to execute arbitrary code with the privileges of the AIDA64 Business application process, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive diagnostic data collected by AIDA64, modify application output or configuration, or crash the application. Because exploitation requires local access and does not escape the application's privilege context, lateral movement potential is limited, though it could serve as a privilege escalation step in a broader attack chain (Feedly, VulnCheck).
A proof-of-concept exploit is publicly available on Exploit-DB (EDB-46639), though automated analysis has not confirmed it as a fully weaponized exploit. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), reflecting very low probability of exploitation in the near term (Exploit-DB, Feedly).
nSEH jump instruction and an SEH handler pointer redirected to a POP POP RET gadget within a loaded module.cmd.exe, powershell.exe, or network utilities) following interaction with the preferences or report wizard UI.SCASD instructions or egg tag markers such as w00tw00t) in process memory dumps of the AIDA64 Business process.The patch status for AIDA64 Business is currently unknown; users should check the official AIDA64 downloads page for an updated version that addresses this vulnerability. As interim mitigations, restrict local access to systems running AIDA64 Business to trusted users only, and apply the principle of least privilege to limit the impact of any exploitation. Implement input validation controls where possible and monitor the SMTP display name and report wizard fields for anomalously long inputs. Organizations should also consider disabling or restricting the SMTP notification functionality if it is not required (AIDA64 Downloads, VulnCheck).
The vulnerability received limited industry attention, with automated CVE alert services such as RedPacketSecurity distributing notifications via social media (Mastodon) shortly after public disclosure in March 2026. No significant vendor statement from FinalWire (AIDA64's developer) has been identified, and no major security researchers have published detailed commentary or analysis beyond the original Exploit-DB submission and VulnCheck advisory (RedPacketSecurity, VulnCheck).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."