CVE-2019-25628Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by crafting malicious URLs. Attackers can create specially crafted URLs with overflowing buffer data that overwrites SEH pointers and executes embedded shellcode when imported through the application's web page import functionality.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-24: 4PoC Mentioned / Linked · 2026-03-24: 1Technical Details · 2026-03-24: 403-24
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2019-25628 Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by… https://www.cve.org/CVERecord?id=CVE-2019-25628 ----- Traducción: CVE-2019-25628 Dow… http://infoflow.cloud`

    Post summary

    The text announces CVE-2019-25628, noting a structured exception handler buffer overflow that enables remote code execution; no PoC, patch, or exploitation reports are mentioned.

    0000020
    60 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2019-25628 Download Accelerator Plus DAP 10.0.6.0 contains a structured exception handler buffer overflow vulnerability that allows remote attackers to execute arbitrary code by… https://www.cve.org/CVERecord?id=CVE-2019-25628

    Post summary

    The text announces CVE-2019-25628, detailing a structured exception handler buffer overflow in Download Accelerator Plus DAP 10.0.6.0 that allows remote attackers to execute arbitrary code.

    00000223
    56.8K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2019-25628: CRITICAL] DAP 10.0.6.0 has a vulnerability allowing remote attackers to execute arbitrary code via malicious URLs, exploiting a structured exception handler buffer overflow issue.#cve,CVE-2019-25628,#cybersecurity https://cvefind.com/CVE-2019-25628

    Post summary

    The post discloses CVE‑2019‑25628, a critical buffer‑overflow vulnerability in DAP 10.0.6.0 that allows remote code execution via malicious URLs; no PoC, exploit code, or patch is provided.

    0000025
    606 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2019-25628: Download Accelerator Plus DAP 10... SEH corruption via malicious URL import = instant RCE with zero user interaction - legacy download manager becomes perf... https://zerodaysignal.com/vulnerability/CVE-2019-25628 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2019‑25628, describing an SEH corruption that enables instant RCE through a malicious URL import, and includes a link that likely hosts additional details or a PoC.

    0000041
    164 followersView on X

Explore more