R 3.4.4 Windows x64 Buffer Overflow SEH DEP ASLR Bypass
Vulnerability Description
R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured exception handler chain pivot and execute arbitrary shellcode with application privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-25485
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- blackleitus
References
Affected Vendor
R-Project
View all reports →