Back to CVE List

CVE-2018-25322

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.4 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Allok Fast AVI MPEG Splitter 1.2 contains a stack based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious license name string. Attackers can craft a payload with 780 bytes of junk data followed by structured shellcode and place it in the License Name field to trigger the overflow and execute code with application privileges.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-121
Source
NVD
Vendor
alloksoft
Product
Fast AVI MPEG Splitter

External References

Discussion (0)

Add Comment

No comments yet. Be the first!