---
id: CVE-2018-25222
title: >-
  SC v7.16 contains a stack-based buffer overflow vulnerability that allows
  local attackers to execute arbitrary code by supplying oversized input that
  exceeds buffer boundaries
summary: >-
  SC v7.16 contains a stack-based buffer overflow vulnerability that allows
  local attackers to execute arbitrary code by supplying oversized input that
  exceeds buffer boundaries. Attackers can craft malicious input strings
  exceeding 1052 b…
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-787
published: '2026-03-28'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T08:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-25222'
references:
  - url: 'https://www.exploit-db.com/exploits/44279'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/sc-stack-based-buffer-overflow-remote-code-execution
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00141
epssPercentile: 0.02891
ingestedAt: '2026-10-07T08:20:03.908Z'
---

## Overview

SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
