R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured exception handler chain pivot and execute arbitrary shellcode with application privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a structured exploit-development walkthrough for CVE-2019-25485, a stack-based buffer overflow in the Windows GUI of R 3.4.4, specifically the 'Edit -> GUI Preferences -> Language for menus and messages' field. It is not a network exploit or framework module; it is a local, manual exploitation lab that generates payload.txt files which the operator pastes into the vulnerable desktop application. Repository structure is split into documentation and exploit stages. The top-level README explains the vulnerability, affected product, and the differing exploitation outcomes on x86 versus x64. Two supporting folders ('01 Environment' and '02 Resources') point to related training repositories. Under 'Vulnerability/Exploit', the code is divided by architecture: x86 and x64. Each architecture has a sequence of small Python 3 scripts representing the exploit workflow: connection/context, fuzzing, offset discovery, control of the instruction pointer, and later exploitation steps. Additional architecture-specific READMEs provide detailed methodology and debugger guidance. The x86 branch is a real exploit chain. It fuzzes the GUI field, finds the EIP offset (292 bytes), confirms EIP control, performs bad-character analysis (documenting \x00 and \x0d as bad chars), selects a JMP ESP gadget in stats.dll at 0x713affbb, and builds a final payload with a NOP sled and embedded x86 shellcode. The documentation states this achieves a reverse shell, and the included shellcode blob plus msfvenom examples support that intent. This makes the x86 side operational exploit code rather than mere detection. The x64 branch is more of an exploitability study than a full weaponized exploit. It fuzzes the same GUI field, finds the RIP offset (300 bytes), confirms partial RIP control using a 6-byte overwrite, and documents gadget hunting. However, the code and notes repeatedly explain why full code execution is blocked: canonical x64 addresses require null bytes, the GUI input path terminates or mangles nulls, no usable post-RIP stack space remains for a ROP chain, and DEP prevents direct execution of controlled data. A sample gadget redirection is included, but the repository explicitly frames x64 as RIP control and analysis, not full RCE. Notable fingerprintable artifacts include the local target executable Rgui.exe, the payload file payload.txt, the x86 gadget module stats.dll at C:\Program Files\R\R-3.4.4\library\stats\libs\i386\stats.dll, the x86 JMP ESP gadget address 0x713affbb, and the x64 demonstration gadget 0x0000000000401668 in Rgui.exe. The only network-like observables are example shellcode-generation parameters in documentation (LHOST 192.168.1.10, LPORT 443); the exploit itself does not perform network communication. Overall, this is a legitimate educational exploit repository centered on a local Windows GUI buffer overflow. Its main capability is full x86 exploitation to shellcode execution/reverse shell, while the x64 content demonstrates crash reproduction, RIP control, and why modern constraints prevent straightforward exploitation through the same vector.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.