CVE-2019-25336: Nsasoft Spotauditor
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
SpotAuditor 5.3.2 contains a local buffer overflow vulnerability in the Base64 Encrypted Password tool that allows attackers to execute arbitrary code by crafting a malicious payload. Attackers can generate a specially crafted Base64 encoded payload to trigger a Structured Exception Handler (SEH) overwrite and execute shellcode on the vulnerable system.
Affected products
- Nsasoft Spotauditor: version 5.3.2 only
Published 2026-02-12. Last modified 2026-06-17.