Description
Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code execution on Windows systems.
Problem types
Product status
Credits
Achilles
References
www.exploit-db.com/exploits/44989 (ExploitDB-44989)
www.boxoft.com/wav-to-wma/ (Product Reference)
www.vulncheck.com/...wma-converter-local-buffer-overflow-seh (VulnCheck Advisory: Boxoft wav-wma Converter 1.0 Local Buffer Overflow SEH)