CVE-2019-25362
Received
Received - Intake
Stack-Based Buffer Overflow in WMV to AVI Converter Enables Remote Code Execution
Publication date: 2026-02-18
Last updated on: 2026-02-27
Assigner: VulnCheck
Description
Description
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| alloksoft | wmv_to_avi_mpeg_dvd_wmv_convertor | 4.6.1217 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |