---
id: CVE-2019-25627
title: FlexHEX 2.71 Local Buffer Overflow via SEH Unicode
summary: >-
  FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name
  field that allows local attackers to execute arbitrary code by triggering a
  structured exception handler (SEH) overflow. Attackers can craft a malicious
  text …
severity: high
cvss: 8.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-434
vendor: Flexhex
product: FlexHEX
affected:
  - FlexHEX 2.71
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-03-24T13:14:53.867717Z'
exploitAvailable: true
published: '2026-03-24'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:20.978Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25627'
references:
  - url: 'https://www.exploit-db.com/exploits/46665'
    label: ExploitDB-46665
  - url: 'http://www.flexhex.com'
    label: Official Product Homepage
  - url: 'http://www.flexhex.com/download/flexhex_setup.exe'
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/flexhex-local-buffer-overflow-via-seh-unicode
    label: 'VulnCheck Advisory: FlexHEX 2.71 Local Buffer Overflow via SEH Unicode'
tags:
  - cve.org
  - exploit-available
epss: 0.00257
epssPercentile: 0.1578
ingestedAt: '2026-10-01T15:48:17.883Z'
---

## Overview

FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.

## Affected

- `FlexHEX 2.71`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
