CVE-2018-25314
8.4Alloksoft · WMV to AVI MPEG DVD WMV Converter
A buffer overflow vulnerability in Alloksoft WMV to AVI MPEG DVD WMV Converter 4.6.1217 allows local attackers to execute arbitrary code via the License Name field.
Executive summary
A local buffer overflow vulnerability in Alloksoft WMV to AVI MPEG DVD WMV Converter 4.6.1217 allows an attacker with local access to achieve arbitrary code execution.
Vulnerability
This is a classic buffer overflow (CWE-120) triggered by providing an oversized string to the License Name field during the product registration process. By overwriting the structured exception handler (SEH), a local, unauthenticated user can bypass standard memory protections to execute malicious shellcode with the privileges of the application.
Business impact
The exploitation of this vulnerability allows for full control of the application process. Given that the software runs with local user privileges, an attacker could potentially install malware, access sensitive user data, or escalate privileges if other system vulnerabilities are present. With a CVSS score of 8.4, this represents a significant security risk for any workstation where this legacy software remains in use.
Remediation
Immediate Action: There is no vendor-supplied patch for this legacy software. Organizations should immediately uninstall this application and seek modern, supported alternatives for media conversion.
Proactive Monitoring: Monitor systems for the execution of unauthorized processes or unexpected crashes of the converter application, which may indicate an exploitation attempt.
Compensating Controls: Ensure that the application is executed within a restricted user environment, such as a least privilege account, to limit the potential impact of successful code execution.
Exploitation status
Public Exploit Available: Yes, a functional exploit exists via ExploitDB (EDB-ID: 44365).
Analyst recommendation
The presence of a functional, public exploit for this vulnerability, combined with the lack of vendor support, creates an unacceptable risk profile. It is strongly recommended that administrators identify all instances of this software within their environment and remove them immediately. If the software is strictly required for legacy workflows, it should be isolated within a non-networked environment to prevent lateral movement or remote interaction.
Sources
Originally found and disclosed by Mohan Ravichandran & Velayutham Selvaraj, per the CVE Program record.
- ExploitDB-44365 Exploit / PoC
- Official Product Homepage
- Product Reference
- VulnCheck Advisory: Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow Third-party advisory