vendor:
Convert Master
by:
Achilles
7.5
CVSS
HIGH
SEH Local Exploit
119
CWE
Product Name: Convert Master
Affected Version From: 1.3.2000
Affected Version To: 1.3.2000
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 7 x64
2020
Boxoft Convert Master 1.3.0 – ‘wav’ SEH Local Exploit
This exploit allows an attacker to execute arbitrary code on a vulnerable system. By providing a specially crafted 'wav' file, an attacker can trigger a buffer overflow condition, overwrite the Structured Exception Handler (SEH) chain, and gain control of the program's execution flow. This exploit includes a bind shell on port 4444.
Mitigation:
To mitigate this vulnerability, users should apply the latest patch or update for Boxoft Convert Master. It is also recommended to avoid opening untrusted 'wav' files.