CVE-2018-25323
HIGH SEVERITYCVSS Score & Metrics
Base Score
8.4 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Description
Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH chain overwrite values, then paste the contents into the License Name field to trigger code execution.
Vulnerability Details
Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
Alloksoft
Product
Allok AVI DivX MPEG to DVD Converter
Discussion (0)
Add Comment
No comments yet. Be the first!