Local Buffer Overflow Vulnerability in 10-Strike LANState by 10-Strike Software
CVE-2018-25255
Key Information:
- Vendor
10-strike
- Status
- Vendor
- CVE Published:
- 4 April 2026
Badges
What is CVE-2018-25255?
The 10-Strike LANState 8.8 is susceptible to a local buffer overflow vulnerability due to inadequate handling of structured exceptions. By creating a specially crafted LSM map file containing malicious payloads in the ObjCaption parameter, local attackers can exploit this weakness to overflow the buffer and overwrite the Structured Exception Handling (SEH) chain. This allows them to execute arbitrary code when the crafted file is opened within the application, posing a significant risk to systems running this version of LANState.
Affected Version(s)
Strike LANState 8.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
