PT-2026-28255 · Passfab · Rar Password Recovery

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2018-25218

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PassFab RAR Password Recovery 9.3.2 contains a structured exception handler (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a payload with a buffer overflow, NSEH jump, and shellcode, then paste it into the 'Licensed E-mail and Registration Code' field during registration to trigger code execution.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2018-25218

Affected Products

Rar Password Recovery