PT-2026-20532 · Unknown+1 · Control Center Pro+1

Published

2026-02-18

·

Updated

2026-02-18

·

CVE-2019-25357

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Control Center PRO version 6.2.9
Description The software contains a stack-based buffer overflow in the username field of the user creation module. This allows attackers to overwrite the Structured Exception Handler (SEH). By crafting a malicious payload exceeding 664 bytes, attackers can inject shellcode and potentially execute arbitrary code on vulnerable Windows systems. The Structured Exception Handler (SEH) is a component of the Windows operating system that handles exceptions during program execution.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the length of the username field during user creation to less than 664 bytes.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25357

Affected Products

Control Center Pro
Windows