Junglewise Threat Intelligence

CVE-2018-25360: AgataSoft Auto PingMaster stack overflow in Trace Route field

CVE-2018-25360 · Severity: high · CVSS 8.4 · Published 2026-05-25

Executive brief

AgataSoft Auto PingMaster, a network diagnostic tool used for monitoring and tracing network routes, is vulnerable to a security flaw that could allow an attacker to take control of a computer. By tricking a user into pasting specially crafted text into the application's Trace Route field, an attacker can run unauthorized commands or software. This could lead to a complete compromise of the local system and the data stored on it.

Technical details

A stack-based buffer overflow (CWE-121) exists in AgataSoft Auto PingMaster 1.5 within the 'Trace Route' host name input field. The vulnerability is triggered when an overly long string containing shellcode and jump instructions is pasted into the application, leading to an overwrite of the Structured Exception Handler (SEH) pointer. A local attacker can exploit this by crafting a malicious text file (e.g., ping.txt) and convincing a user to paste its contents into the 'Host name' field and clicking 'Get IP from host name'. Successful exploitation allows for arbitrary code execution with the privileges of the application. No patch is currently documented for this legacy version.

Affected products

  • AgataSoft Auto PingMaster 1.5

Timeline

  • 2018-08-03: disclosed: Initial exploit code published by researcher bzyo
  • 2026-05-25: advisory: NVD/VulnCheck advisory published

References