CVE-2019-25331

8.4

AVS4YOU · AVS Audio Converter

AVS Audio Converter 9.1 contains a local stack-based buffer overflow vulnerability in the Exit folder input field, allowing an attacker to overwrite CPU registers and potentially execute arbitrary code.

Executive summary

A local buffer overflow vulnerability in AVS Audio Converter 9.1 could allow a local attacker to execute arbitrary code by manipulating input fields.

Vulnerability

This is a stack-based buffer overflow (CWE-121) triggered by providing a specially crafted string into the Exit folder configuration field. The vulnerability allows an unauthenticated local user to overwrite CPU registers, such as the EIP, to hijack the application process.

Business impact

Successful exploitation of this vulnerability allows a local user to gain unauthorized control over the AVS Audio Converter process. Given that the application may run with elevated privileges, this could result in full system compromise, loss of data confidentiality, and potential lateral movement within the local environment. The high CVSS score of 8.4 reflects the severe impact on system integrity and availability, even though the attack vector is restricted to a local user.

Remediation

Immediate Action: Discontinue the use of version 9.1 and update to the latest available version of AVS Audio Converter provided by the vendor.

Proactive Monitoring: Monitor system logs for unexpected application crashes or access violations associated with the AVS Audio Converter executable.

Compensating Controls: Since this is a local attack, ensure that standard users do not have administrative privileges on the host machine to limit the impact of potential code execution.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exploit is available via ExploitDB (EDB-ID 47788).

Analyst recommendation

The vulnerability presents a significant risk to local system security. IT administrators should identify any instances of AVS Audio Converter 9.1 within their environment and upgrade to a patched version immediately. If an update is not feasible, restrict access to the application to minimize the attack surface until the software can be updated.

Sources

Originally found and disclosed by ZwX, per the CVE Program record.