CVE-2019-25363

7.5

Alloksoft · WMV to AVI MPEG DVD WMV Convertor

Alloksoft WMV to AVI MPEG DVD WMV Convertor 4.6.1217 is vulnerable to a stack-based buffer overflow, allowing an attacker to cause an application crash via an oversized license input.

Executive summary

A stack-based buffer overflow in Alloksoft WMV to AVI MPEG DVD WMV Convertor 4.6.1217 poses a critical risk of application denial of service.

Vulnerability

The application suffers from a stack-based buffer overflow (CWE-121) in the license input field. An attacker can provide a 6000-byte payload into the License Name and License Code field to trigger a crash, effectively performing a denial of service attack against the software.

Business impact

Successful exploitation results in a denial of service, rendering the conversion software unusable. While the impact is primarily availability-based, such disruptions can impede critical business workflows reliant on media processing. The CVSS score of 7.5 reflects the high impact on local system availability, even if the attack requires physical or local user interaction.

Remediation

Immediate Action: There is no official vendor patch available for this legacy software. Organizations should discontinue the use of this product or restrict its execution to isolated, non-critical environments.

Proactive Monitoring: Monitor system event logs and error reports for recurring crashes associated with this specific application binary.

Compensating Controls: Since this is a local client application, ensure that the software is executed with the least privilege necessary, and use endpoint security solutions to monitor for abnormal memory execution patterns.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit Database (EDB-ID: 47563).

Analyst recommendation

Given the lack of vendor support and the availability of a public proof-of-concept, users are strongly advised to remove the affected software from all production systems. If the application is required for legacy operations, it should be strictly sandboxed to prevent potential lateral impact or system instability.

Sources

Originally found and disclosed by Nithoshitha S, per the CVE Program record.