CVE-2025-70330 is a file parsing vulnerability in Easy Grade Pro 4.1.0.2 affecting the handling of proprietary .EGP gradebook files. A crafted but otherwise valid .EGP file can be modified at specific offsets so that, when the application parses the file, it performs an out-of-bounds memory read. The resulting invalid memory access causes an unhandled access violation and crashes the application. Based on the provided information, this is a local denial-of-service issue triggered when a user opens the malicious file.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: educational write-up and PoC for a local denial-of-service vulnerability in Orbis Software Ltd. Easy Grade Pro, involving malformed proprietary .EGP gradebook files. The documented issue is an offset/length trust bug in the file parser leading to CWE-125 out-of-bounds read and an unhandled access violation during memcpy()-style copying. Structure: - Root README.md: long-form technical narrative explaining why the repo exists, high-level vulnerability description, crash behavior, and PoC parameters (injection offset 548, 21 bytes of 0x41). - Vulnerability/03 Proof of Concept/EasyGradePro_DoS.py: the only code file; a Python3 script that takes an existing valid .EGP file and produces a crashing variant by inserting a fixed payload at a fixed offset. - Vulnerability/04 CVE Request/README.md: notes for submitting a CVE request (includes suggested description, affected versions, attack vector). - Vulnerability/05 CVSS v4.0/README.md: CVSS v4.0 scoring rationale (local, low complexity, user opens file; availability impact high). - Vulnerability/06 Emails/1_OrbisSoftware.txt: responsible disclosure email draft. - 01 Environment/README.md and 02 Resources/README.md: links to the author’s environment/resources repos. Exploit capabilities (PoC): - Generates a malformed .EGP file by inserting 21 'A' bytes at offset 548 into a user-supplied input .EGP. - Does not perform network activity, memory corruption primitives, or code execution; it is strictly a file-based crash generator. - Includes a basic sanity check to ensure the insertion offset is within the input file length. Targeting/trigger: - Local attack vector requiring user interaction: victim opens the crafted .EGP in Easy Grade Pro. - Intended impact: reliable application crash (DoS) via out-of-bounds read during parsing/copying due to missing bounds validation on reconstructed offsets.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.