


Perceptive Security
SOC/SIEM Consultancy

Base64 Decoder 1.1.2 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by triggering a structured excep…
Published:
23 maart 2026 om 23:00:00
Alert date:
24 maart 2026 om 16:16:53
Source:
nvd.nist.gov
Security Tools
Base64 Decoder version 1.1.2 contains a critical stack-based buffer overflow vulnerability that enables local attackers to execute arbitrary code. The vulnerability can be exploited by crafting malicious input files that overflow a buffer and overwrite the Structured Exception Handler (SEH) chain. Attackers use a POP-POP-RET gadget address to control execution flow and employ an egghunter payload to locate and execute shellcode. This allows complete code execution on the target system. The vulnerability has been assigned CVE-2019-25634 and has exploit code publicly available on Exploit-DB.
Technical details
Mitigation steps:
Affected products:
Base64 Decoder
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2019-25634
http://4mhz.de/b64dec.html
http://4mhz.de/download.php?file=b64dec-1-1-2.zip
https://www.exploit-db.com/exploits/46625
https://www.vulncheck.com/advisories/base64-decoder-local-buffer-overflow-seh-egghunter
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
