Impact
The flaw is a structured exception handling (SEH) buffer overflow located in the 'Save Path for Snapshot and Record file' field of iSmartViewPro version 1.5. By providing a payload exceeding 260 bytes through the System Setup interface, a local attacker can overwrite SEH records and execute arbitrary shellcode with the privileges of the application. This vulnerability is a classic example of CWE‑120 and allows attackers to run code with the application’s rights, potentially compromising the host and any services the application controls.
Affected Systems
Securimport iSmartViewPro 1.5 is the only product explicitly listed as affected. No other versions are mentioned in the available data, so the scope is limited to that installation.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity risk, while the EPSS score of less than 1 percent suggests a low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning widespread, documented exploitation has not yet been observed. The attack requires local access to the System Setup interface, typically through an administrator account; thus, it is a local privilege escalation risk. If exploited, the attacker gains application‑level execution, which can lead to full system compromise.
OpenCVE Enrichment