216.73.216.233

CVE-2018-25373

· Published 25/05/2026 15:16 · Modified 26/05/2026 19:47

Labels: CVE-2018-25373 2026-05-25CVE-2018-25373CWE-121[email protected]

Essential information

Published
25/05/2026 15:16
Modified
26/05/2026 19:47
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

SocuSoft DVD Photo Slideshow Professional 8.07 contains a stack-based buffer overflow vulnerability in the registration name field that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious text file with carefully constructed payload containing junk bytes, SEH chain overwrite, and shellcode, then paste the contents into the Registration Name field via Help > Register to trigger code execution.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
socusoft / dvd photo slideshow professional cpe:2.3:a:socusoft:dvd_photo_slideshow_professional:8.07:*:*:*:*:*:*:*

References