CVE-2018-25222 PUBLISHED

SC v7.16 Stack-Based Buffer Overflow Remote Code Execution

Assigner: VulnCheck
Reserved: 28.03.2026 Published: 28.03.2026 Updated: 28.03.2026

SC v7.16 contains a stack-based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying oversized input that exceeds buffer boundaries. Attackers can craft malicious input strings exceeding 1052 bytes to overwrite the instruction pointer and execute shellcode in the application context.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.6

Product Status

Vendor sc
Product SC
Versions
  • Version 7.16 is affected

Credits

  • Juan Sacco - http://www.exploitpack.com <jsacco@exploitpack.com> finder

References

Problem Types

  • Out-of-bounds Write CWE