Junglewise Threat Intelligence

CVE-2018-25373: SocuSoft DVD Photo Slideshow Professional stack overflow in registration field

CVE-2018-25373 · Severity: high · CVSS 8.4 · Published 2026-05-25

Executive brief

SocuSoft DVD Photo Slideshow Professional is a Windows application used to create slideshows and burn them to DVDs. A security flaw in the software's registration process allows a local user to execute unauthorized commands on the computer. By pasting a specially crafted string into the registration name field, an attacker could gain full control over the system or install malicious software.

Technical details

A stack-based buffer overflow (CWE-121) exists in SocuSoft DVD Photo Slideshow Professional 8.07 within the 'Registration Name' input field. The vulnerability is triggered when a user navigates to Help > Register and inputs an excessively long string. An attacker can exploit this by overwriting the Structured Exception Handler (SEH) chain to redirect execution flow to a malicious payload (shellcode). While the attack requires local access to the application interface, it does not require prior administrative privileges to execute code in the context of the running application. Public exploit code is available that demonstrates achieving code execution via a crafted text file.

Affected products

  • SocuSoft DVD Photo Slideshow Professional 8.07 and earlier

Timeline

  • 2018-09-06: disclosed: Initial exploit code published by T3jv1l
  • 2026-05-25: advisory: CVE published and assigned by VulnCheck

References