
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25633 is a structured exception handling (SEH) buffer overflow vulnerability in AIDA64 Extreme version 5.99.4900 that allows local attackers to execute arbitrary code with application privileges. Attackers exploit the vulnerability by supplying malicious input through the email preferences and report wizard interfaces, specifically via the Display name field and Load from file parameter. The CVE was published on March 24, 2026, and carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.6 (High) (VulnCheck Advisory, Exploit-DB).
The vulnerability is classified as CWE-787 (Out-of-bounds Write), manifesting as a SEH-based buffer overflow. An attacker with local access can craft an oversized payload and inject it into the Display name field within the email preferences interface or the Load from file parameter in the report wizard, overwriting the structured exception handler chain on the stack. This technique — commonly paired with egghunter shellcode — allows the attacker to redirect execution flow and run arbitrary shellcode within the context of the AIDA64 Extreme process (VulnCheck Advisory, Exploit-DB).
Successful exploitation grants a local, low-privileged attacker the ability to execute arbitrary code with the privileges of the AIDA64 Extreme application, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive system information collected by AIDA64, modify application data, or cause a denial of service. The scope is limited to the local machine, but the ability to run arbitrary code could facilitate privilege escalation or lateral movement if AIDA64 is run with elevated privileges (VulnCheck Advisory).
A proof-of-concept exploit is publicly available on Exploit-DB (EDB-46636), though automated analysis has not confirmed it as a fully weaponized exploit (Exploit-DB). There is no confirmed evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (VulnCheck Advisory).
cmd.exe, powershell.exe, or network tools) that are not part of normal application behavior.No official vendor patch has been confirmed as available for CVE-2019-25633 at the time of disclosure. As interim mitigations, restrict access to AIDA64 Extreme to trusted users only, and disable or limit access to the email preferences and report wizard features if they are not operationally required. Organizations should monitor for suspicious process activity originating from AIDA64 and consider upgrading to the latest available version of AIDA64 Extreme from the vendor, as newer releases may address this issue (VulnCheck Advisory, AIDA64 Official).
Coverage of CVE-2019-25633 has been limited to automated CVE aggregation and alert services such as RedPacket Security and CVEFeed, with no notable independent researcher commentary or significant media coverage identified. The vulnerability received routine tracking on VulDB and Bluesky CVE feed accounts, reflecting standard community monitoring rather than elevated concern (RedPacket Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."