PT-2026-20532 · Unknown+1 · Control Center Pro+1
Published
2026-02-18
·
Updated
2026-02-18
·
CVE-2019-25357
CVSS v3.1
8.4
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Control Center PRO version 6.2.9
Description
The software contains a stack-based buffer overflow in the username field of the user creation module. This allows attackers to overwrite the Structured Exception Handler (SEH). By crafting a malicious payload exceeding 664 bytes, attackers can inject shellcode and potentially execute arbitrary code on vulnerable Windows systems. The Structured Exception Handler (SEH) is a component of the Windows operating system that handles exceptions during program execution.
Recommendations
Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict the length of the username field during user creation to less than 664 bytes.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Control Center Pro
Windows