CVE-2018-25377: Socusoft Flash Slideshow Maker Professional
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Flash Slideshow Maker Professional 5.20 contains a buffer overflow vulnerability in the registration dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload and paste it into the Name and Code fields of the Help > Register dialog to trigger a reverse shell with system privileges.
Affected products
- Socusoft Flash Slideshow Maker Professional: version 5.20 only
Published 2026-05-25. Last modified 2026-07-24.