vendor:
WMV to AVI MPEG DVD WMV Convertor
by:
Doan Nguyen (4ll4u)
7.5
CVSS
HIGH
Buffer Overflow
Buffer Overflow
CWE
Product Name: WMV to AVI MPEG DVD WMV Convertor
Affected Version From: 4.6.1217
Affected Version To: 4.6.1217
Patch Exists: NO
Related CWE:
CPE: a:alloksoft:wmv_to_avi_mpeg_dvd_wmv_convertor:4.6.1217
Platforms Tested: Windows XP SP3
2019
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 – Buffer OverFlow (SEH)
The WMV to AVI MPEG DVD WMV Convertor version 4.6.1217 is vulnerable to a buffer overflow vulnerability, which can be exploited to execute arbitrary code. By pasting specially crafted content from EVIL.txt into the 'License Name and License Code' field and clicking 'OK', an attacker can trigger the buffer overflow and gain a bind shell on port 4444.
Mitigation:
The vendor has not released a patch for this vulnerability. Users are advised to avoid using the affected software or to use alternative software from trusted sources.