CVE-2018-25360: Agatasoft Auto Pingmaster

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

AgataSoft Auto PingMaster 1.5 contains a stack-based buffer overflow vulnerability in the Trace Route host name field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious ping.txt file with shellcode and jump instructions that overwrite the SEH handler pointer to achieve code execution when the file contents are pasted into the application.

Affected products

Published 2026-05-25. Last modified 2026-07-23.