2026-03-26 13:24CVE-2018-25213VulnCheck
PUBLISHED5.2CWE-787

Nsauditor 3.0.28.0 Local SEH Buffer Overflow

Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges.

Problem type

Affected products

Nsauditor

Nsauditor Local SEH Buffer Overflow

3.0.28.0 - AFFECTED

References

JSON source

https://cveawg.mitre.org/api/cve/CVE-2018-25213
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2018-25213",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-03-26T14:46:20.591Z",
    "dateReserved": "2026-03-26T13:15:11.554Z",
    "datePublished": "2026-03-26T13:24:14.608Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-03-26T13:24:14.608Z"
      },
      "datePublic": "2018-12-15T00:00:00.000Z",
      "title": "Nsauditor 3.0.28.0 Local SEH Buffer Overflow",
      "descriptions": [
        {
          "lang": "en",
          "value": "Nsauditor 3.0.28.0 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying malicious input to the DNS Lookup tool. Attackers can craft a payload with SEH chain overwrite and inject shellcode through the DNS Query field to achieve code execution with application privileges."
        }
      ],
      "affected": [
        {
          "vendor": "Nsauditor",
          "product": "Nsauditor Local SEH Buffer Overflow",
          "versions": [
            {
              "version": "3.0.28.0",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Out-of-bounds Write",
              "cweId": "CWE-787",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.exploit-db.com/exploits/46005",
          "name": "ExploitDB-46005",
          "tags": [
            "exploit"
          ]
        },
        {
          "url": "http://www.nsauditor.com",
          "name": "Official Product Homepage",
          "tags": [
            "product"
          ]
        },
        {
          "url": "http://www.nsauditor.com/downloads/nsauditor_setup.exe",
          "name": "Product Reference",
          "tags": [
            "product"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/nsauditor-local-seh-buffer-overflow",
          "name": "VulnCheck Advisory: Nsauditor 3.0.28.0 Local SEH Buffer Overflow",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 8.4,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Achilles",
          "type": "finder"
        }
      ]
    },
    "adp": [
      {
        "providerMetadata": {
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP",
          "dateUpdated": "2026-03-26T14:46:20.591Z"
        },
        "title": "CISA ADP Vulnrichment",
        "metrics": [
          {}
        ]
      }
    ]
  }
}