Junglewise Threat Intelligence

CVE-2019-25666: Nsauditor SpotAuditor buffer overflow in Base64 Password Decoder

CVE-2019-25666 · Severity: medium · CVSS 6.2 · Published 2026-04-05

Vendors: Nsasoft.

Executive brief

SpotAuditor, a password recovery and auditing tool, contains a security flaw in its password decoding component. A local user can cause the application to crash by entering an excessively long string of text into the Base64 decoder tool. This results in a denial of service, preventing the software from functioning correctly until it is restarted.

Technical details

A local buffer overflow vulnerability exists in SpotAuditor version 3.6.7 and potentially earlier versions within the 'Base64 Password Decoder' component. The flaw is rooted in an out-of-bounds write (CWE-787) triggered when the application processes an oversized Base64 string provided through the decoder interface. An attacker with local access to the system can exploit this by pasting a specially crafted long string into the 'Base64 Encrypted Password' field and clicking 'Decrypt'. Successful exploitation results in an immediate application crash (Denial of Service). While currently documented as a DoS, buffer overflows of this nature can sometimes be leveraged for arbitrary code execution depending on memory protections in place.

Affected products

  • Nsauditor SpotAuditor 3.6.7 and earlier

Timeline

  • 2019-01-30: disclosed: Vulnerability discovered by Rafael Pedrero
  • 2019-02-04: other: Proof of concept exploit published on Exploit-DB
  • 2026-04-05: advisory: CVE-2019-25666 published via VulnCheck/NVD

References

Related threats