CVE-2018-25283
SEH Buffer Overflow in iSmartViewPro 1.5 Enables Code Execution
Publication date: 2026-04-26
Last updated on: 2026-04-26
Assigner: VulnCheck
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-120 | The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
The vulnerability exists in iSmartViewPro version 1.5 and is a structured exception handling (SEH) buffer overflow. It occurs in the 'Save Path for Snapshot and Record file' field, where local attackers can input a crafted payload exceeding 260 bytes. This overflow allows attackers to overwrite SEH records and execute arbitrary code with the application's privileges.
How can this vulnerability impact me? :
This vulnerability can allow local attackers to execute arbitrary code on the affected system with the same privileges as the application. This could lead to unauthorized actions such as installing malware, stealing data, or disrupting system operations.