216.73.217.22

CVE-2018-25323

· Published 17/05/2026 13:16 · Modified 18/05/2026 17:29

Labels: CVE-2018-25323 2026-05-17CVE-2018-25323CWE-120[email protected]

Essential information

Published
17/05/2026 13:16
Modified
18/05/2026 17:29
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Allok AVI DivX MPEG to DVD Converter 2.6.1217 contains a structured exception handler buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious payload. Attackers can craft a text file with a specially crafted buffer containing shellcode and SEH chain overwrite values, then paste the contents into the License Name field to trigger code execution.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
allok / avi divx mpeg to dvd converter cpe:2.3:a:allok:avi_divx_mpeg_to_dvd_converter:2.6.1217:*:*:*:*:*:*:*

References