Local buffer overflow vulnerability in Faleemi Desktop Software by Faleemi
CVE-2018-25263
Key Information:
- Vendor
Faleemi
- Status
- Vendor
- CVE Published:
- 26 April 2026
Badges
What is CVE-2018-25263?
Faleemi Desktop Software version 1.8.2 is susceptible to a local buffer overflow vulnerability in the Device alias field. This flaw enables local attackers to exploit a structured exception handler (SEH) overwrite. By crafting a malicious payload and pasting it into the Device alias field within the Managing Log interface, attackers can execute arbitrary code, demonstrated through a proof-of-concept using a calculator application. It is crucial for users of this software to assess their security posture and implement necessary updates or mitigations against potential exploits.
Affected Version(s)
Faleemi Desktop Software 1.8.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
