CVE-2018-25220Disclosure(bochs_project / bochs)

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the application. Attackers can craft a malicious payload with 1200 bytes of padding followed by a return-oriented programming chain to overwrite the instruction pointer and execute shell commands with application privileges.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • bochs

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-28); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Products
bochs

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-28: 3Mentions · 2026-03-29: 2PoC Mentioned / Linked · 2026-03-28: 2Technical Details · 2026-03-28: 3Technical Details · 2026-03-29: 103-2803-29
Signal classification3 categories
Disclosure
360.0%
PoC
120.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-283
Disclosure2PoC1
2026-03-292
Disclosure1General1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2018-25220 Bochs 2.6-5 contains a stack-based buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized input string to the applica… https://www.cve.org/CVERecord?id=CVE-2018-25220

    Post summary

    The post reports a stack‑based buffer overflow in Bochs 2.6‑5 that can lead to arbitrary code execution, but offers no PoC, exploit, or patch information.

    0001051
    56.9K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2018-25220 | CVSS 9.8 🔴 CVE-2017-20229 | CVSS 9.8 🔴 CVE-2018-25223 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    A brief announcement highlighting three high‑severity CVEs (CVE‑2018‑25220, CVE‑2017‑20229, CVE‑2018‑25223) with a link for more information.

    0000028
    5.6K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2018-25220 📊 Severity: 9.8 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2018-25220 #CVE-2018-25220 #CVE #Critical #CyberSecurity #InfoSec https://t.co/LCufoIabOu

    Post summary

    The tweet announces the discovery of CVE-2018-25220, rating it as critical with a severity score of 9.8 and noting it affects multiple unspecified products.

    0000023
    123 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2018-25220: CRITICAL] Bochs 2.6-5 vulnerability allows attackers to execute code by exploiting a buffer overflow with an oversized input string. Malicious payload can trigger shell commands.#cve,CVE-2018-25220,#cybersecurity https://cvefind.com/CVE-2018-25220

    Post summary

    This tweet discloses a critical Bochs vulnerability (CVE-2018-25220) involving a buffer overflow that allows execution of shell commands, yet it lacks a link to a PoC, explicit exploit code, or patch information.

    0000023
    617 followersView on X
  • 0day Signal@0dayPublishing
    PoC

    🚨 CVE-2018-25220: Bochs 2.6-5 Buffer Overflow Remo... Stack smashing with ROP chains on a 6-year-old emulator - 1200 bytes of padding gets you shell, and there's already wor... https://zerodaysignal.com/vulnerability/CVE-2018-25220 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet highlights a proof‑of‑concept stack‑overflow exploit for CVE‑2018‑25220, detailing ROP usage and key payload size, but it does not discuss active attacks or patch status.

    0000038
    194 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appbochs_projectbochs2.6.5--

Explore more