vendor:
AVS Audio Converter
by:
boku
N/A
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: AVS Audio Converter
Affected Version From: 9.1.2.600
Affected Version To: 9.1.2.600
Patch Exists: NO
Related CWE:
CPE: a:avs:avs_audio_converter:9.1.2.600
Platforms Tested: Windows 10 Home 1909, Windows 7 Enterprise
2019
AVS Audio Converter 9.1.2.600 – Stack Overflow (PoC)
This is a proof-of-concept exploit for a stack overflow vulnerability in AVS Audio Converter version 9.1.2.600. By providing a specially crafted payload in a file, an attacker can trigger a stack overflow and potentially execute arbitrary code.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid opening untrusted files in AVS Audio Converter.