Description
AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.
Problem types
Product status
Credits
boku
References
www.exploit-db.com/exploits/47810 (ExploitDB-47810)
www.avs4you.com/ (Software Vendor Homepage)
www.exploit-db.com/exploits/47788 (ExploitDB-47788)
www.vulncheck.com/...ries/avs-audio-converter-stack-overflow (VulnCheck Advisory: AVS Audio Converter 9.1.2.600 - Stack Overflow)