CVE-2018-25303
8.4Alloksoft · Allok Video to DVD Burner
Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow in the License Name field that allows local attackers to execute arbitrary code via a malicious input string.
Executive summary
A stack-based buffer overflow vulnerability in Allok Video to DVD Burner 2.6.1217 allows local attackers to achieve arbitrary code execution by triggering a structured exception handler overwrite.
Vulnerability
This is a stack-based buffer overflow (CWE-121) located in the License Name field of the registration interface. An unauthenticated local attacker can provide a specially crafted input string to overwrite the structured exception handler (SEH) chain and execute arbitrary code.
Business impact
Successful exploitation of this vulnerability allows a local attacker to gain control over the affected system with the privileges of the user running the application. Given the CVSS score of 8.4, this represents a high severity risk that could lead to full system compromise, unauthorized data access, or the deployment of persistent malware within the local environment.
Remediation
Immediate Action: As no official patch is currently available for this legacy software, users are advised to uninstall the application or restrict access to the executable to prevent unauthorized local execution.
Proactive Monitoring: Review local host logs for unexpected application crashes or anomalous behavior occurring during registration processes.
Compensating Controls: Ensure that endpoint protection solutions are configured to detect and block buffer overflow attempts and unauthorized memory execution patterns.
Exploitation status
Public Exploit Available: Yes — a functional local exploit targeting this specific vulnerability is documented in the Exploit Database (EDB-ID: 44518).
Analyst recommendation
The presence of a public exploit targeting this stack-based buffer overflow necessitates immediate action to mitigate the risk of local code execution. Organizations should prioritize the removal of this software from affected systems, as no vendor-provided security update is available to remediate the underlying flaw.
Sources
Originally found and disclosed by T3jv1l, per the CVE Program record.
- ExploitDB-44518 Exploit / PoC
- Official Product Homepage
- VulnCheck Advisory: Allok Video to DVD Burner 2.6.1217 Buffer Overflow SEH Third-party advisory