Buffer Overflow Vulnerability in AIDA64 Business by AIDA64
CVE-2019-25631
Key Information:
- Vendor
Aida64
- Status
- Vendor
- CVE Published:
- 24 March 2026
Badges
What is CVE-2019-25631?
AIDA64 Business 5.99.4900 is susceptible to a structured exception handling (SEH) buffer overflow vulnerability. This flaw allows local attackers to potentially execute arbitrary code by manipulating SEH pointers through crafted input. Attackers can exploit this issue via the SMTP display name field in the application’s preferences or through the report wizard feature, enabling them to deploy egg hunter shellcode and trigger the overflow, which allows actions to be executed with the same privileges as the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AIDA64 Business 5.99.4900 #
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
