vendor:
River_Past_Audio_Converter
by:
Matteo Malvica
7.5
CVSS
HIGH
Local Buffer Overflow (SEH)
119
CWE
Product Name: River_Past_Audio_Converter
Affected Version From: Unknown
Affected Version To: 7.7.16
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 - 10.0.17134.1
2019
River_Past_Audio_Converter – Buffer Overflow (SEH)
This exploit takes advantage of a buffer overflow vulnerability in River_Past_Audio_Converter. By pasting a specially crafted content into the 'Lame_enc.dll' name field, an attacker can trigger a buffer overflow and gain control of the program. This can be used to execute arbitrary code or launch a bind shell on port 4444.
Mitigation:
Update to a patched version of River_Past_Audio_Converter or use alternative software.