Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-34096 — SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint. | Kitploit
Tools/GitHubGitHub/themalwareguardian/cve-2025-34096
Vulnerability AnalysisExploitationReverse EngineeringShellcodeWeb Application ExploitationPenetration TestingLearning & EducationPayload DevelopmentBinary Exploitation
GitHubthemalwareguardian/cve-2025-34096

CVE-2025-34096

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.

View Repository
96 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🐞 CVE-2025-34096: Easy File Sharing Web Server 7.2 - Stack-Based Buffer Overflow (SEH)

SEH-based buffer overflow in Easy File Sharing Web Server 7.2, reachable through the password recovery endpoint.




📑 Table of Contents

  • Why this repository exists
  • Why this vulnerability is interesting
  • Context and affected software
  • About the vulnerability
  • Triggering the crash
  • Exploitation



🎓 Why this repository exists

This repository was created as part of the material I use when teaching vulnerability research and exploit development, particularly when introducing the concept of SEH (Structured Exception Handler) overflows and ROP (Return-Oriented Programming) chains.

It is related to my talk "The Path That Leads to Your First CVE". In that talk, I explain that there are different entry points into vulnerability research, and that studying publicly documented CVEs in legacy software is one of the most accessible paths for beginners.

This CVE was chosen because it demonstrates a complete and realistic exploitation scenario:

  • The target is a publicly available Windows application.
  • The crash is not a simple EIP overwrite, it involves SEH overwrite and stack pivoting.
  • The vulnerable endpoint requires no authentication, making it a true unauthenticated remote code execution primitive.
  • The exploit can optionally be extended with a ROP chain to bypass DEP/NX, demonstrating how the same SEH overflow can be adapted to more hardened environments.

The goal is to use this case as a stepping stone between introductory buffer overflow exercises and more advanced exploit development concepts.




💡 Why this vulnerability is interesting

This vulnerability affects Easy File Sharing Web Server 7.2, a lightweight Windows web server application that was widely used for simple file sharing. The software was written without modern security mitigations in mind. What makes this case particularly interesting from a teaching perspective is the combination of factors involved:

  • The vulnerable endpoint is a POST request, making it easy to reproduce with standard HTTP tools.
  • The /sendemail.ghp endpoint is part of the application's email notification feature and is accessible to any remote attacker without credentials. This represents a more impactful attack scenario than vulnerabilities that require prior access.
  • The overflow is SEH-based, meaning the crash does not overwrite the return address directly. Instead, it corrupts the Structured Exception Handler chain on the stack, requiring a different exploitation technique.
  • DEP bypassing is optional, meaning the exploit works with a direct SEH + short jump + shellcode approach on systems where DEP is disabled. But, if DEP is enabled, the exploit can be extended with a ROP chain using gadgets from loaded modules to call VirtualProtect and mark the shellcode region as executable before transferring control.

This combination makes CVE-2025-34096 an excellent case for teaching exploit development techniques in a realistic unauthenticated attack scenario.




🔍 Context and affected software

Easy File Sharing Web Server 7.2 is a lightweight Windows application built for sharing files over HTTP. Beyond basic file browsing and user accounts, it includes a password recovery feature, a form that lets users enter their email address to receive their forgotten credentials.

That form posts to /sendemail.ghp. The handler that processes the Email field copies the value straight into a fixed-size stack buffer with no length check. The endpoint needs no authentication, so there is nothing standing between a remote attacker and the vulnerable code path.

Key technical details:

  • Vulnerability type: Stack-based buffer overflow (SEH overwrite)
  • Affected version: Easy File Sharing Web Server 7.2
  • Affected endpoint: POST /sendemail.ghp
  • Vulnerable parameter: Email
  • Authentication required: No
  • Impact: Unauthenticated remote code execution



⚠️ About the vulnerability

Easy File Sharing Web Server processes HTTP POST requests directed to /sendemail.ghp as part of its email notification feature. The Email parameter accepted by this endpoint is copied into a local stack buffer without any length check.

A simplified version of the vulnerable logic looks like this:

char email_buffer[256];

strcpy(email_buffer, user_input);

Since the destination buffer has a fixed size and the input length is not validated, sending a sufficiently long string in the Email field causes the copy to write past the end of the buffer.

As more data is written, the stack layout becomes corrupted. Unlike a simple return address overwrite, the overflow reaches the Structured Exception Handler (SEH) chain stored on the stack. When an exception is triggered as a result of the corrupted stack, the OS walks the SEH chain and transfers control to the attacker-controlled handler address.

The exploitation flow therefore follows the SEH overwrite technique:

  1. A long input overwrites the stack, including the nSEH and SEH handler pointers.
  2. An exception is triggered due to the memory corruption.
  3. The OS invokes the overwritten handler address.
  4. A POP POP RETN gadget is used to transfer execution to the nSEH area.
  5. A short jump forward skips over the SEH record and redirects execution to the shellcode area.
  6. The shellcode runs.

This makes the vulnerability more complex to exploit than a basic EIP overwrite, but also more representative of real-world scenarios.




💥 Triggering the crash

The crash can be reproduced by sending a long string in the Email parameter of a POST request to /sendemail.ghp. No authentication is required. Example using Python:

import socket

HOST = '127.0.0.1'
PORT = 80

request = (
	'POST /sendemail.ghp HTTP/1.1\r\n'
	'Email=' + 'A' * 5000 + '&getPassword=Get+Password'
).encode('utf-8')

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((HOST, PORT))
s.send(request)
s.close()

When executed under a debugger, the crash shows a corrupted SEH chain and an access violation, confirming that user-controlled data has overwritten the exception handler pointer.




💣 Exploitation

The goal of this repository is not only to demonstrate the crash, but also to walk through the complete exploitation process step by step, following the methodology used when developing real SEH-based exploits.

To keep the main README clean, the detailed exploitation notes, scripts, and debugger steps are placed inside the Vulnerability 📂 folder of this repository.

There you will find the complete workflow used to exploit this CVE, including:

  • Fuzzing the Email parameter to identify the crash.
  • Offset discovery to locate the exact position of nSEH and SEH on the stack.
  • Bad character analysis to identify bytes that corrupt the payload.
  • SEH chain overwrite using a POP POP RETN gadget from a loaded module.
  • Shellcode placement and execution.
  • Optional: ROP chain construction to bypass DEP by calling VirtualProtect through gadgets from loaded modules.
Download Tool