CVE-2018-25212
HIGHBoxoft wav-wma Converter 1.0 Local Buffer Overflow SEH
Title source: cnaDescription
Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code execution on Windows systems.
Exploits (1)
Scores
CVSS v3
8.4
EPSS
0.0002
EPSS Percentile
4.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-787
Status
published
Products (2)
Boxoft/WAV to WMA Converter
1.0
boxoft/wav_to_wma_converter
1.0
Published
Mar 26, 2026
Tracked Since
Mar 26, 2026