CVE-2018-25322
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.4 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and place it in the License Name field to trigger the overflow and execute code with application privileges.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-121
Source
NVD
Vendor
alloksoft
Product
Fast AVI MPEG Splitter
Discussion (0)
Add Comment
No comments yet. Be the first!