nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25362 CVE-2019-25362
CRITICAL
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow
Record summary
CVE-2019-25362 has a selected CVSS score of 9.3 (critical); EIP currently links 2 catalogued exploits.
Description
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WMV to AVI MPEG DVD WMV ConvertorBrowse Alloksoft / WMV to AVI MPEG DVD WMV Convertor | CVE List | 4.6.1217 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBWMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Denial of ServiceExploitDB exploitby Nithoshitha SNot analyzed1 file
ExploitDBWMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow (SEH)ExploitDB exploitby 4ll4uNot analyzed1 file
References
6Vendor Homepageproduct
https://www.alloksoft.com/ Software Download Pageproduct
https://www.alloksoft.com/wmv.htm Exploit Database Entry 47563exploit
https://www.exploit-db.com/exploits/47563 ExploitDB-47568exploit
https://www.exploit-db.com/exploits/47568 VulnCheck Advisory: WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlowThird-party advisory
https://www.vulncheck.com/advisories/wmv-to-avi-mpeg-dvd-wmv-convertor-buffer-overflow