CVE-2018-25302
Last modified
CVE-2018-25302 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Allok AVI to DVD SVCD VCD Converter 4.0.1217 contains a structured exception handling (SEH) based buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Name field. Attackers can craft a payload with junk data, NSEH bypass, SEH handler address, and shellcode that triggers the overflow when pasted into the License Name field and the Register button is clicked, resulting in code execution.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2018-25302?
How severe is CVE-2018-25302?
How do I fix CVE-2018-25302?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-25296P10 Central Management Software 1.4.13 contains a buffer ove…6.8
- CVE-2018-25297Wansview 1.0.2 contains a buffer overflow vulnerability that…6.9
- CVE-2018-25298Merge PACS 7.0 contains a cross-site request forgery vulnera…6.9
- CVE-2018-25299Prime95 29.4b8 contains a local buffer overflow vulnerabilit…8.6
- CVE-2018-25300XATABoost CMS 1.0.0 contains a union-based SQL injection vul…8.8
- CVE-2018-25301Easy MPEG to DVD Burner 1.7.11 contains a structured excepti…8.6
- CVE-2018-25303Allok Video to DVD Burner 2.6.1217 contains a stack-based bu…8.6
- CVE-2018-25304Free Download Manager 2.0 Build 417 contains a local buffer …8.6
- CVE-2018-25305librsvg2-bin 2.40.13 contains a buffer overflow vulnerabilit…6.9
- CVE-2018-25306PDFunite 0.41.0 contains a buffer overflow vulnerability tha…5.5
- CVE-2018-25307SysGauge Pro 4.6.12 contains a local buffer overflow vulnera…8.6
- CVE-2018-25308BuddyPress Xprofile Custom Fields Type 2.6.3 contains a remo…8.8
Are you affected by CVE-2018-25302?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
