vendor:
A-PDF All to MP3 Converter
by:
modpr0be
7.5
CVSS
HIGH
SEH Overflow
119
CWE
Product Name: A-PDF All to MP3 Converter
Affected Version From: 1.1.2000
Affected Version To: 1.1.2000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3
2010
A-PDF All to MP3 Converter v.1.1.0 Universal Local SEH Exploit
This exploit takes advantage of a SEH (Structured Exception Handler) overflow vulnerability in A-PDF All to MP3 Converter v.1.1.0. By sending a specially crafted WAV file as input, an attacker can trigger the overflow and execute arbitrary code. The exploit has been tested on Windows XP SP3.
Mitigation:
The vendor has not released a patch for this vulnerability. To mitigate the risk, users are advised to avoid opening untrusted WAV files with A-PDF All to MP3 Converter v.1.1.0.