---
id: CVE-2025-70330
title: >-
  Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of
  proprietary .EGP gradebook files
summary: >-
  Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of
  proprietary .EGP gradebook files. By modifying specific fields at precise
  offsets within an otherwise valid .EGP file, an attacker can trigger an
  out-of-bounds …
severity: low
cvss: 3.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L'
cwe:
  - CWE-125
published: '2026-03-11'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-70330'
references:
  - url: 'https://github.com/TheMalwareGuardian/CVE-2025-70330'
    label: cve@mitre.org
tags:
  - nvd
  - exploit-available
epss: 0.00148
epssPercentile: 0.03318
ingestedAt: '2026-07-06T16:44:34.522Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/TheMalwareGuardian/CVE-2025-70330'
  checkedAt: '2026-09-25T08:20:48.410Z'
exploitAvailable: true
---

## Overview

Easy Grade Pro 4.1.0.2 contains a file parsing logic flaw in the handling of proprietary .EGP gradebook files. By modifying specific fields at precise offsets within an otherwise valid .EGP file, an attacker can trigger an out-of-bounds memory read during parsing. This results in an unhandled access violation and application crash, leading to a local denial-of-service condition when the crafted file is opened by a user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
