Vulnerability record · CVE-2019-16724 · published 24 September 2019
CVE-2019-16724: File Sharing Wizard HTTP POST SEH buffer overflow allows RCE
UUpredsun · File Sharing Wizard
File Sharing Wizard 1.5.0 contains a Structured Exception Handler (SEH) based buffer overflow reachable through an HTTP POST parameter. A remote attacker can send a crafted request to overwrite the SEH chain and execute arbitrary code. The flaw is a classic buffer overflow (CWE-120) similar to CVE-2010-2330 and CVE-2010-2331.
Description
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Exception Handler (SEH) based buffer overflow in an HTTP POST parameter, a similar issue to CVE-2010-2330 and CVE-2010-2331.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityRemote, unauthenticated code execution with public exploit code and a very high EPSS score makes this an urgent patching priority.
What it is
File Sharing Wizard 1.5.0 contains a Structured Exception Handler (SEH) based buffer overflow reachable through an HTTP POST parameter. A remote attacker can send a crafted request to overwrite the SEH chain and execute arbitrary code. The flaw is a classic buffer overflow (CWE-120) similar to CVE-2010-2330 and CVE-2010-2331.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the File Sharing Wizard service, which typically means full control of the affected host. No privilege escalation step is required beyond reaching the vulnerable HTTP endpoint.
Attack surface
The flaw is reached over the network via an HTTP POST parameter, so it is remotely triggerable. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed.
Exploitation
Public exploit code exists, as shown by the Packet Storm and Exploit-DB references tagged Exploit. The CVE is not in CISA KEV, but EPSS is very high (0.72, 99.4th percentile), indicating elevated likelihood of exploitation activity.
What to do
- Patch or upgrade File Sharing Wizard past 1.5.0; if no fixed release exists, retire or replace the product.
- Remove the service from internet-facing exposure and restrict HTTP access to trusted networks.
- Place the service behind a reverse proxy or WAF with rules blocking oversized or malformed POST parameters.
- Run the service under a low-privilege account with minimal filesystem and network permissions.
- Monitor vendor and exploit databases for a fixed version, since the record does not name one.
Detection
- Inspect HTTP POST request logs for unusually long parameter values or repeated crash-inducing payloads against the File Sharing Wizard endpoint.
- Monitor for process crashes and SEH-related exception events on hosts running File Sharing Wizard.
- Alert on unexpected child processes or outbound connections spawned by the File Sharing Wizard service.
- Use network IDS signatures for known SEH overflow exploit patterns targeting this product.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-16724 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-16724), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.