CVE-2019-25362

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
Configurations

Configuration 1 (hide)

cpe:2.3:a:alloksoft:wmv_to_avi_mpeg_dvd_wmv_convertor:4.6.1217:*:*:*:*:*:*:*

History

27 Feb 2026, 15:17

Type Values Removed Values Added
References () https://www.alloksoft.com/ - Product () https://www.alloksoft.com/ - Not Applicable, URL Repurposed
References () https://www.alloksoft.com/wmv.htm - Product () https://www.alloksoft.com/wmv.htm - Not Applicable, URL Repurposed

26 Feb 2026, 21:48

Type Values Removed Values Added
References () https://www.alloksoft.com/ - () https://www.alloksoft.com/ - Product
References () https://www.alloksoft.com/wmv.htm - () https://www.alloksoft.com/wmv.htm - Product
References () https://www.exploit-db.com/exploits/47563 - () https://www.exploit-db.com/exploits/47563 - Exploit, VDB Entry
References () https://www.exploit-db.com/exploits/47568 - () https://www.exploit-db.com/exploits/47568 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/wmv-to-avi-mpeg-dvd-wmv-convertor-buffer-overflow - () https://www.vulncheck.com/advisories/wmv-to-avi-mpeg-dvd-wmv-convertor-buffer-overflow - Third Party Advisory
Summary
  • (es) WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contiene una vulnerabilidad de desbordamiento de búfer que permite a los atacantes ejecutar código arbitrario sobrescribiendo los campos de nombre de licencia y código de licencia. Los atacantes pueden crear una carga útil maliciosa de 6000 bytes para activar un bind shell en el puerto 4444 explotando un desbordamiento de búfer basado en pila en el manejo de entrada de la aplicación.
First Time Alloksoft
Alloksoft wmv To Avi Mpeg Dvd Wmv Convertor
CPE cpe:2.3:a:alloksoft:wmv_to_avi_mpeg_dvd_wmv_convertor:4.6.1217:*:*:*:*:*:*:*

18 Feb 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 22:16

Updated : 2026-02-27 15:17


NVD link : CVE-2019-25362

Mitre link : CVE-2019-25362

CVE.ORG link : CVE-2019-25362


JSON object : View

Products Affected

alloksoft

  • wmv_to_avi_mpeg_dvd_wmv_convertor
CWE
CWE-787

Out-of-bounds Write