Stack-Based Buffer Overflow in SocuSoft DVD Photo Slideshow Professional
CVE-2018-25373
Key Information:
- Vendor
Socusoft
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2018-25373?
SocuSoft DVD Photo Slideshow Professional 8.07 is vulnerable to a stack-based buffer overflow in the registration name field. This vulnerability allows local attackers to execute arbitrary code through structured exception handling exploitation. By crafting a malicious text file with a specifically structured payload containing junk bytes and shellcode, an attacker can cause a failure in the SEH chain and trigger code execution via the Registration Name field under the Help > Register section of the application.
Affected Version(s)
DVD Photo Slideshow Professional 8.07
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
