Home

Description

JetAudio jetCast Server 2.0 contains a stack-based buffer overflow vulnerability in the Log Directory configuration field that allows local attackers to overwrite structured exception handling pointers. Attackers can inject alphanumeric encoded shellcode through the Log Directory field to trigger an SEH exception handler and execute arbitrary code with application privileges.

PUBLISHED Reserved 2026-03-22 | Published 2026-03-22 | Updated 2026-03-25 | Assigner VulnCheck




HIGH: 8.6CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
HIGH: 8.4CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

Out-of-bounds Write

Product status

2.0
affected

Credits

Connor McGarr (https://connormcgarr.github.io) finder

References

www.exploit-db.com/exploits/46854 (ExploitDB-46854) exploit

www.jetaudio.com/ (Official Product Homepage) product

www.jetaudio.com/...Audio/Download/jetCast/build/JCS2000.exe (Product Reference) product

www.vulncheck.com/...etcast-server-local-seh-buffer-overflow (VulnCheck Advisory: JetAudio jetCast Server 2.0 Local SEH Buffer Overflow) third-party-advisory

cve.org (CVE-2019-25609)

nvd.nist.gov (CVE-2019-25609)

Download JSON