vendor:
Allok RM RMVB to AVI MPEG DVD Converter
by:
Antonio de la Piedra
7.5
CVSS
HIGH
Stack Overflow (SEH)
121
CWE
Product Name: Allok RM RMVB to AVI MPEG DVD Converter
Affected Version From: 3.6.1217
Affected Version To: 3.6.1217
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 SP1 32-bit
2020
Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 – Stack Overflow (SEH)
The exploit allows an attacker to execute arbitrary code by exploiting a stack overflow vulnerability in Allok RM RMVB to AVI MPEG DVD Converter version 3.6.1217. By pasting the contents of poc_seh.txt into the License Name input field, an attacker can execute the calc.exe application.
Mitigation:
Update to a patched version of Allok RM RMVB to AVI MPEG DVD Converter. Avoid pasting untrusted content into input fields.