# CVE-2019-25620

## Summary

- **CVE ID:** CVE-2019-25620
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-168
- **Published:** Mar 23, 2026
- **Last Modified:** Mar 23, 2026

## Description

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the vulnerability by entering arbitrary characters during application runtime, causing the application to become unresponsive or terminate abnormally.

## Affected Products

- Pixarra — Tree Studio (2.17)

## References

- [CNA](https://www.exploit-db.com/exploits/46125)
- [CNA](http://www.pixarra.com/)
- [CNA](http://www.pixarra.com/uploads/9/4/6/3/94635436/tbtreestudio_install.exe)
- [CNA](https://www.vulncheck.com/advisories/tree-studio-denial-of-service-via-malformed-input)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.17%
- **EPSS Percentile:** 7.0

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._