๐Ÿ” CVE Alert

CVE-2019-25650

HIGH 8.4

River Past CamDo 3.7.6 Structured Exception Handler Buffer Overflow

CVSS Score
8.4
EPSS Score
0.0%
EPSS Percentile
0th

River Past CamDo 3.7.6 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the Lame_enc.dll name field. Attackers can craft a payload with a 280-byte buffer, NSEH jump instruction, and SEH handler address pointing to a pop-pop-ret gadget to trigger code execution and establish a bind shell on port 3110.

CWE CWE-787
Vendor riverpast
Product river past camdo
Published Mar 26, 2026
Last Updated Mar 26, 2026
Stay Ahead of the Next One

Get instant alerts for riverpast river past camdo

Be the first to know when new high vulnerabilities affecting riverpast river past camdo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

riverpast / River Past CamDo
3.7.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
exploit-db.com: https://www.exploit-db.com/exploits/46335 en.softonic.com: https://en.softonic.com/download/river-past-cam-do/windows/post-download?sl=1 vulncheck.com: https://www.vulncheck.com/advisories/river-past-camdo-structured-exception-handler-buffer-overflow

Credits

Achilles