vendor:
Allok Fast AVI MPEG Splitter
by:
Mohan Ravichandran & Velayutham Selvaraj
7.5
CVSS
HIGH
Stack Based Buffer Overflow
121
CWE
Product Name: Allok Fast AVI MPEG Splitter
Affected Version From: 1.2
Affected Version To: 1.2
Patch Exists: NO
Related CWE:
CPE: a:alloksoft:allok_fast_avi_mpeg_splitter:1.2
Platforms Tested: Windows XP Service Pack 3 (Version 2002) & Windows 7 x64 Ultimate
2018
Stack Based Buffer Overflow in Allok Fast AVI MPEG Splitter 1.2 (Windows XP SP3)
The exploit allows an attacker to execute arbitrary code by exploiting a stack-based buffer overflow vulnerability in Allok Fast AVI MPEG Splitter 1.2. By creating a specially crafted file and running the exploit code, the attacker can trigger the buffer overflow and gain control over the target system. The exploit has been tested on Windows XP SP3 and Windows 7 x64 Ultimate.
Mitigation:
The vendor has not released a patch for this vulnerability. Users are advised to avoid using Allok Fast AVI MPEG Splitter 1.2 or to apply a workaround by blocking the execution of the vulnerable software.