Junglewise Threat Intelligence

CVE-2018-25258: The R Project RGui buffer overflow in GUI preferences dialog

CVE-2018-25258 · Severity: high · CVSS 8.4 · Published 2026-04-12

Executive brief

RGui is a graphical interface for the R statistical computing environment. A security flaw in version 3.5.0 allows a local user to execute unauthorized commands on a computer by entering specially crafted text into the application's preference settings. This could lead to a full system compromise, data theft, or the installation of malicious software.

Technical details

A stack-based buffer overflow exists in RGui 3.5.0 within the 'GUI preferences' dialog. Specifically, the 'Language for menus and messages' field does not properly validate the length of input strings. A local attacker can exploit this by providing a long, malicious string that overwrites the Structured Exception Handler (SEH). By utilizing a Return-Oriented Programming (ROP) chain to call VirtualAlloc, an attacker can bypass Data Execution Prevention (DEP) and achieve arbitrary code execution. This issue was reportedly fixed in version 3.5.1.

Affected products

  • The R Project for Statistical Computing RGui 3.5.0

Timeline

  • 2018-09-01: other: Vulnerability discovered
  • 2019-01-10: disclosed: Exploit published on Exploit-DB
  • 2026-04-12: advisory: NVD/VulnCheck advisory published

References