CVE-2018-25212
8.4Boxoft · WAV to WMA Converter
Boxoft WAV to WMA Converter 1.0 contains a local buffer overflow vulnerability that allows unauthenticated attackers to achieve arbitrary code execution via a specially crafted WAV file.
Executive summary
A critical local buffer overflow vulnerability in Boxoft WAV to WMA Converter 1.0 allows attackers to execute arbitrary code on the host system through malicious media files.
Vulnerability
This is a local buffer overflow vulnerability (CWE-787) involving structured exception handling within the application. An unauthenticated attacker can trigger this flaw by providing a specially crafted WAV file containing excessive data and ROP gadgets to overwrite the exception chain.
Business impact
The successful exploitation of this vulnerability allows for full code execution on the underlying Windows system with the privileges of the user running the application. This could lead to total system compromise, unauthorized access to sensitive local data, or the installation of persistent malicious software. Given the CVSS score of 8.4, this vulnerability represents a high risk to organizational security, particularly if the software is utilized in environments where users frequently process untrusted media files.
Remediation
Immediate Action: As no official patch is currently identified, users should immediately cease use of Boxoft WAV to WMA Converter 1.0 and uninstall the software from all systems.
Proactive Monitoring: Security teams should monitor endpoint logs for unusual application crashes or process executions originating from media conversion utilities, which may indicate attempted exploitation.
Compensating Controls: Implement strict application allowlisting to prevent the execution of unauthorized or legacy software that lacks vendor support.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the Exploit-DB entry 44989.
Analyst recommendation
Due to the lack of a vendor-provided patch and the availability of a public exploit, this software poses an unacceptable security risk. Organizations must prioritize the removal of Boxoft WAV to WMA Converter 1.0 from all workstations. If a WAV to WMA conversion capability is required, transition to a modern, actively maintained alternative that adheres to current secure development standards.
Sources
Originally found and disclosed by Achilles, per the CVE Program record.
- ExploitDB-44989 Exploit / PoC
- Product Reference
- VulnCheck Advisory: Boxoft wav-wma Converter 1.0 Local Buffer Overflow SEH Third-party advisory