Record summary

CVE-2019-25362 has a selected CVSS score of 9.3 (critical); EIP currently links 2 catalogued exploits.

Description

WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.6.1217affected

Proofs of concept

2

Catalogued exploits

ExploitDBWMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Denial of ServiceExploitDB exploitby Nithoshitha SNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details
ExploitDBWMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow (SEH)ExploitDB exploitby 4ll4uNot analyzed1 file
ExploitDB

PoC details

References

6