CVE-2018-25314

HIGH

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-25314. PoCs published by Mohan Ravichandran and Velayutham Selvaraj.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217. It crafts a malicious input file that triggers a SEH-based overflow, leading to arbitrary code execution (e.g., launching calculator).

Description

Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 contains a buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious input containing shellcode with structured exception handler (SEH) overwrite to bypass protections and execute code with application privileges.

Exploits (1)

exploitdb WORKING POC
by Mohan Ravichandran and Velayutham Selvaraj · pythonlocalwindows
https://www.exploit-db.com/exploits/44365

This exploit demonstrates a buffer overflow vulnerability in Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217. It crafts a malicious input file that triggers a SEH-based overflow, leading to arbitrary code execution (e.g., launching calculator).

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217
No auth needed
Prerequisites: Python 2.7 · Vulnerable software installed on Windows XP SP3
devstral-2 · analyzed Apr 30, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-44365
https://www.exploit-db.com/exploits/44365
Product product
Official Product Homepage
http://www.alloksoft.com
Product product
Product Reference
http://www.alloksoft.com/wmv.htm
Third Party Advisory third-party-advisory
VulnCheck Advisory: Allok soft WMV to AVI MPEG DVD WMV Converter 4.6.1217 Buffer Overflow
https://www.vulncheck.com/advisories/allok-soft-wmv-to-avi-mpeg-dvd-wmv-converter-buffer-overflow

Scores

CVSS v3 8.4
EPSS 0.0016
EPSS Percentile 5.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
Alloksoft/WMV to AVI MPEG DVD WMV Converter 4.6.1217
Published Apr 29, 2026
Tracked Since Apr 30, 2026