CVE-2018-25211

7.8

Alloksoft · Allok Video Splitter

Allok Video Splitter 3.1.1217 is susceptible to a buffer overflow vulnerability via the License Name field, which may allow local attackers to cause a denial of service or execute arbitrary code.

Executive summary

A local buffer overflow vulnerability in Allok Video Splitter 3.1.1217 allows potential arbitrary code execution or service disruption through a malformed license input.

Vulnerability

This vulnerability is a buffer overflow (CWE-787) triggered when an attacker provides an oversized string exceeding 780 bytes into the License Name registration field. The flaw allows a local, unprivileged attacker to crash the application or potentially execute arbitrary code upon clicking the Register button.

Business impact

Successful exploitation of this vulnerability could lead to a complete denial of service for the affected software, disrupting business workflows that rely on video processing. While the CVSS score of 7.8 indicates high severity, the requirement for local access and user interaction limits the attack surface; however, the potential for arbitrary code execution remains a significant security concern for workstations where this software is deployed.

Remediation

Immediate Action: There is no official patch available for this legacy software. Organizations should immediately uninstall Allok Video Splitter 3.1.1217 if it is not essential to business operations.

Proactive Monitoring: Monitor endpoint logs for application crashes or unexpected service termination events associated with the Allok Video Splitter process.

Compensating Controls: Restrict local user permissions to prevent the installation or execution of unauthorized or legacy software that lacks active vendor support.

Exploitation status

Public Exploit Available: Yes, a proof of concept exists on ExploitDB (EDB-ID 44605).

Analyst recommendation

Given the lack of a vendor-supplied patch and the presence of a functional proof-of-concept exploit, this vulnerability poses a persistent risk to any environment using the affected software. Security teams should prioritize the removal of this application from all systems to eliminate the risk of local code execution and service disruption.

Sources

Originally found and disclosed by Achilles, per the CVE Program record.