CVE-2019-25633
FinalWire AIDA64 vulnerability analysis and mitigation

Overview

CVE-2019-25633 is a structured exception handling (SEH) buffer overflow vulnerability in AIDA64 Extreme version 5.99.4900 that allows local attackers to execute arbitrary code with application privileges. Attackers exploit the vulnerability by supplying malicious input through the email preferences and report wizard interfaces, specifically via the Display name field and Load from file parameter. The CVE was published on March 24, 2026, and carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.6 (High) (VulnCheck Advisory, Exploit-DB).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), manifesting as a SEH-based buffer overflow. An attacker with local access can craft an oversized payload and inject it into the Display name field within the email preferences interface or the Load from file parameter in the report wizard, overwriting the structured exception handler chain on the stack. This technique — commonly paired with egghunter shellcode — allows the attacker to redirect execution flow and run arbitrary shellcode within the context of the AIDA64 Extreme process (VulnCheck Advisory, Exploit-DB).

Impact

Successful exploitation grants a local, low-privileged attacker the ability to execute arbitrary code with the privileges of the AIDA64 Extreme application, resulting in high confidentiality, integrity, and availability impact on the affected system. An attacker could read sensitive system information collected by AIDA64, modify application data, or cause a denial of service. The scope is limited to the local machine, but the ability to run arbitrary code could facilitate privilege escalation or lateral movement if AIDA64 is run with elevated privileges (VulnCheck Advisory).

Exploitability

A proof-of-concept exploit is publicly available on Exploit-DB (EDB-46636), though automated analysis has not confirmed it as a fully weaponized exploit (Exploit-DB). There is no confirmed evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013% (0.000130), indicating a very low probability of exploitation in the near term (VulnCheck Advisory).

Exploitation steps

  1. Reconnaissance: Identify systems running AIDA64 Extreme version 5.99.4900 locally or via asset inventory tools.
  2. Access the vulnerable interface: Open AIDA64 Extreme and navigate to the email preferences settings or the report wizard interface.
  3. Craft the payload: Generate an oversized buffer (e.g., a long string of 'A' characters) combined with egghunter shellcode and a target SEH overwrite address, using tools such as Metasploit's pattern_create or a custom Python script.
  4. Inject into vulnerable field: Paste or load the crafted payload into the Display name field (email preferences) or supply it via the Load from file parameter in the report wizard.
  5. Trigger the overflow: Submit or apply the input, causing the application to process the oversized buffer, overwrite the SEH chain, and redirect execution to the attacker-controlled shellcode.
  6. Execute shellcode: The egghunter locates the staged shellcode in memory and executes it with AIDA64 application privileges, enabling arbitrary command execution (Exploit-DB, VulnCheck Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the AIDA64 Extreme process (e.g., cmd.exe, powershell.exe, or network tools) that are not part of normal application behavior.
  • File System: Unusual files written to disk by the AIDA64 process, particularly in temp directories or user-writable locations; unexpected configuration file modifications in AIDA64's settings directory.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing AIDA64 Extreme with exception codes consistent with access violations or SEH chain corruption.
  • Network: Outbound network connections initiated by the AIDA64 process to unexpected external IP addresses, which may indicate shellcode establishing a reverse shell.

Mitigation and workarounds

No official vendor patch has been confirmed as available for CVE-2019-25633 at the time of disclosure. As interim mitigations, restrict access to AIDA64 Extreme to trusted users only, and disable or limit access to the email preferences and report wizard features if they are not operationally required. Organizations should monitor for suspicious process activity originating from AIDA64 and consider upgrading to the latest available version of AIDA64 Extreme from the vendor, as newer releases may address this issue (VulnCheck Advisory, AIDA64 Official).

Community reactions

Coverage of CVE-2019-25633 has been limited to automated CVE aggregation and alert services such as RedPacket Security and CVEFeed, with no notable independent researcher commentary or significant media coverage identified. The vulnerability received routine tracking on VulDB and Bluesky CVE feed accounts, reflecting standard community monitoring rather than elevated concern (RedPacket Security).

Additional resources


SourceThis report was generated using AI

Related FinalWire AIDA64 vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2019-25633HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25631HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25629HIGH8.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoNoMar 24, 2026
CVE-2019-25360HIGH8.4
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 18, 2026
CVE-2020-37140MEDIUM4.6
  • FinalWire AIDA64 logoFinalWire AIDA64
  • cpe:2.3:a:aida64:aida64
NoYesFeb 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management