vendor:
Fast AVI MPEG Splitter
by:
Shubham Singh
7.8
CVSS
HIGH
SEH Overwrite POC
119
CWE
Product Name: Fast AVI MPEG Splitter
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: YES
Related CWE: N/A
CPE: a:alloksoft:fast_avi_mpeg_splitter:1.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP Service Pack 3 x86
2018
Allok Fast AVI MPEG Splitter 1.2 SEH Overwrite POC
Allok Fast AVI MPEG Splitter 1.2 is vulnerable to a SEH overwrite vulnerability. This vulnerability can be exploited by an attacker to execute arbitrary code in the context of the application. The vulnerability is triggered when a specially crafted license key is entered into the application. This causes the application to crash and allows an attacker to overwrite the SEH handler with arbitrary code.
Mitigation:
Upgrade to the latest version of Allok Fast AVI MPEG Splitter 1.2 or apply the vendor-supplied patch.