High severity8.4NVD Advisory· Published Mar 26, 2026· Updated Mar 31, 2026
CVE-2018-25219
CVE-2018-25219
Description
PassFab Excel Password Recovery 8.3.1 contains a structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload in the registration code field. Attackers can craft a buffer overflow payload with a pop-pop-ret gadget and shellcode that triggers code execution when pasted into the Licensed E-mail and Registration Code field during the registration process.
Affected products
1- cpe:2.3:a:passfab:excel_password_recovery:*:*:*:*:*:*:*:*Range: <=8.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/46301nvdExploitVDB Entry
- www.vulncheck.com/advisories/passfab-excel-password-recovery-seh-buffer-overflownvdThird Party Advisory
- www.passfab.com/downloads/passfab-excel-password-recovery.exenvdProduct
- www.passfab.com/products/excel-password-recovery.htmlnvdProduct
News mentions
0No linked articles in our index yet.