Back to CVE List

CVE-2018-25323

HIGH SEVERITY

CVSS Score & Metrics

Base Score
8.4 / 10
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vulnerability Description

Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH chain overwrite values, then paste the contents into the License Name field to trigger code execution.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-120
Source
NVD
Vendor
Alloksoft
Product
Allok AVI DivX MPEG to DVD Converter

External References

Discussion (0)

Add Comment

No comments yet. Be the first!