Junglewise Threat Intelligence

CVE-2019-25660: Hainsoft LanHelper buffer overflow in Form Send Message

CVE-2019-25660 · Severity: medium · CVSS 6.2 · Published 2026-04-05

Executive brief

Hainsoft LanHelper, a network management tool for Windows, is vulnerable to a local buffer overflow. An attacker with access to the system can crash the application by inputting an excessively long string into the message field. This results in a denial-of-service condition, preventing the software from functioning correctly.

Technical details

A local buffer overflow vulnerability exists in Hainsoft LanHelper 1.74 due to improper bounds checking on input strings. Specifically, the 'Form Send Message' feature within the 'NT-Utilities' component fails to handle large data inputs. An attacker can trigger an out-of-bounds write (CWE-787) by pasting approximately 6000 bytes of data into the 'Message text' field. This leads to an application crash and a denial-of-service (DoS) condition. The vulnerability was verified on Windows XP SP3, and a public Proof of Concept (PoC) is available.

Affected products

  • Hainsoft LanHelper 1.74

Timeline

  • 2019-01-31: disclosed: Vulnerability discovered and PoC released on Exploit-DB
  • 2026-04-05: advisory: NVD/VulnCheck advisory published

References