vendor:
Allok MOV Converter
by:
Shubham Singh
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Allok MOV Converter
Affected Version From: 4.6.1217
Affected Version To: 4.6.1217
Patch Exists: NO
Related CWE:
CPE: a:alloksoft:allok_mov_converter:4.6.1217
Platforms Tested: Windows XP Service Pack 3 x86
2018
Allok MOV Converter 4.6.1217 – Buffer Overflow (SEH)
This exploit takes advantage of a buffer overflow vulnerability in Allok MOV Converter 4.6.1217. By running the python exploit script, a new file named 'exploit.txt' is created. The content of 'exploit.txt' is then pasted into the License name field of the Allok MOV Converter program, triggering the buffer overflow and causing a calculator to pop up.
Mitigation:
Apply the latest patch from the vendor. Do not download or open files from untrusted sources.