Junglewise Threat Intelligence

CVE-2019-25689: Socusoft HTML5 Video Player buffer overflow in registration dialog

CVE-2019-25689 · Severity: high · CVSS 8.4 · Published 2026-04-12

Executive brief

HTML5 Video Player is a Windows application used to encode and embed videos into websites. A security flaw in the software's registration process allows an attacker to take control of a user's computer if they can convince the user to paste a specially crafted, long serial key into the registration window. This could lead to the installation of malware or unauthorized access to the system.

Technical details

A local stack-based buffer overflow exists in HTML5 Video Player version 1.2.5. The vulnerability is located in the 'Help Register' dialog within the 'KEY CODE' input field. By supplying a string exceeding 997 bytes, an attacker can overwrite the instruction pointer (EIP) to redirect execution flow. While the vulnerability is local, it can be exploited without administrative privileges to execute arbitrary shellcode on the host system. Public exploits demonstrate code execution by bypassing standard protections on Windows XP and later systems.

Affected products

  • Socusoft HTML5 Video Player 1.2.5

Timeline

  • 2019-01-27: disclosed: Initial exploit code authored by Telspace Systems
  • 2019-01-29: other: Exploit published on Exploit-DB
  • 2026-04-12: advisory: CVE formally published/assigned via VulnCheck

References