HeidiSQL Portable Denial-of-Service Vulnerability via Buffer Overflow

Vulnerability

A denial-of-service vulnerability has been identified in HeidiSQL Portable version 10.1.0.5464. This vulnerability allows local attackers to crash the application by entering an excessively long string in the password field. During the login process for Microsoft SQL Server, attackers can paste a buffer overflow payload into the password input, triggering the application to crash.

Impact

Exploitation of this vulnerability leads to a crash of the HeidiSQL application, causing a denial-of-service condition.

Reproduction

To reproduce this vulnerability, first run a Python script that generates a buffer overflow payload by writing a string of 2000 'A' characters to a text file. After executing the script, open the file and copy its contents to the clipboard. Then, launch HeidiSQL Portable 10.1.0.5464 and create a new connection. Select 'Microsoft SQL Server (TCP/IP)' as the network type and enable 'Prompt for credentials'. When the login window appears, paste the clipboard contents into the password field and click 'Login'. The application will crash, demonstrating the denial-of-service vulnerability.

Added: Mar 22, 2026, 2:32 PM
Updated: Mar 22, 2026, 2:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
4.6
remediation
0.0
relevance
4.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.