vendor:
Allok WMV to AVI MPEG DVD WMV Converter
by:
Mohan Ravichandran & Velayutham Selvaraj
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: Allok WMV to AVI MPEG DVD WMV Converter
Affected Version From: 4.6.1217
Affected Version To: 4.6.1217
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2018
Allok soft WMV to AVI MPEG DVD WMV Converter – Buffer Overflow Vulnerability
This exploit takes advantage of a buffer overflow vulnerability in Allok soft WMV to AVI MPEG DVD WMV Converter. By creating a specially crafted file and pasting its contents into the License Name field, an attacker can execute arbitrary code and open the calculator application on the target system.
Mitigation:
Update to a non-vulnerable version of the software. No mitigation provided in the description.