← Vulnerability feed

Vulnerability record · CVE-2019-16724 · published 24 September 2019

CVE-2019-16724: File Sharing Wizard HTTP POST SEH buffer overflow allows RCE

UUpredsun · File Sharing Wizard

File Sharing Wizard 1.5.0 contains a Structured Exception Handler (SEH) based buffer overflow reachable through an HTTP POST parameter. A remote attacker can send a crafted request to overwrite the SEH chain and execute arbitrary code. The flaw is a classic buffer overflow (CWE-120) similar to CVE-2010-2330 and CVE-2010-2331.

9.8 CVSS 3.1 Critical EPSS 72% · top 0.6% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score, v2 7.5
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityRemote, unauthenticated code execution with public exploit code and a very high EPSS score makes this an urgent patching priority.

What it is

File Sharing Wizard 1.5.0 contains a Structured Exception Handler (SEH) based buffer overflow reachable through an HTTP POST parameter. A remote attacker can send a crafted request to overwrite the SEH chain and execute arbitrary code. The flaw is a classic buffer overflow (CWE-120) similar to CVE-2010-2330 and CVE-2010-2331.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the File Sharing Wizard service, which typically means full control of the affected host. No privilege escalation step is required beyond reaching the vulnerable HTTP endpoint.

Attack surface

The flaw is reached over the network via an HTTP POST parameter, so it is remotely triggerable. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.

Exploitation

Public exploit code exists, as shown by the Packet Storm and Exploit-DB references tagged Exploit. The CVE is not in CISA KEV, but EPSS is very high (0.72, 99.4th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Patch or upgrade File Sharing Wizard past 1.5.0; if no fixed release exists, retire or replace the product.
  • Remove the service from internet-facing exposure and restrict HTTP access to trusted networks.
  • Place the service behind a reverse proxy or WAF with rules blocking oversized or malformed POST parameters.
  • Run the service under a low-privilege account with minimal filesystem and network permissions.
  • Monitor vendor and exploit databases for a fixed version, since the record does not name one.

Detection

  • Inspect HTTP POST request logs for unusually long parameter values or repeated crash-inducing payloads against the File Sharing Wizard endpoint.
  • Monitor for process crashes and SEH-related exception events on hosts running File Sharing Wizard.
  • Alert on unexpected child processes or outbound connections spawned by the File Sharing Wizard service.
  • Use network IDS signatures for known SEH overflow exploit patterns targeting this product.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-16724 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-18655Upredsun file sharing wizard out-of-bounds write vulnerabilityFile Sharing Wizard version 1.5.0 build 2008 is affected by a Structured Exception Handler based buffer overflow vulnerability. An unauthenticated at…EPSS 15%9.8CVE-2019-17415Upredsun file sharing wizard classic buffer overflow vulnerabilityA Structured Exception Handler (SEH) based buffer overflow in File Sharing Wizard 1.5.0 26-8-2008 allows remote unauthenticated attackers to execute …EPSS 4.4%7.5CVE-2024-0418Upredsun file sharing wizard improper resource shutdown vulnerabilityA vulnerability has been found in iSharer and upRedSun File Sharing Wizard up to 1.5.0 and classified as problematic. This vulnerability affects unkn…EPSS 1.3%5.5CVE-2025-43520Apple OS kernel memory corruption via malicious appA memory corruption flaw (classic buffer overflow) in Apple's kernel was fixed across iOS, iPadOS, macOS, tvOS, visionOS and watchOS. A malicious app…KEVEPSS 0.43%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed9.8CVE-2022-37055D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_mainD-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The f…KEVEPSS 56%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.8CVE-2020-15069Sophos XG Firewall buffer overflow in HTTP/S BookmarksSophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clien…KEVEPSS 11%analysed

Source: NIST National Vulnerability Database (record CVE-2019-16724), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.