CVE-2019-25318
HIGHAVS Audio Converter <9.1.2.600 - Code Injection
Title source: llmDescription
AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.
Exploits (2)
Scores
CVSS v3
8.8
EPSS
0.0004
EPSS Percentile
13.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-121
Status
published
Products (1)
Avs4You/AVS Audio Converter
9.1.2.600
Published
Feb 12, 2026
Tracked Since
Feb 18, 2026