Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input string with 780 bytes of junk data followed by SEH chain pointers and shellcode, then paste it into the License Name field during registration to achieve code execution.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Apr 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alloksoft
Alloksoft allok Video To Dvd Burner |
|
| Vendors & Products |
Alloksoft
Alloksoft allok Video To Dvd Burner |
Wed, 29 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allok Video to DVD Burner 2.6.1217 contains a stack-based buffer overflow vulnerability in the License Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overwrite. Attackers can craft a malicious input string with 780 bytes of junk data followed by SEH chain pointers and shellcode, then paste it into the License Name field during registration to achieve code execution. | |
| Title | Allok Video to DVD Burner 2.6.1217 Buffer Overflow SEH | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-29T19:24:35.902Z
Updated: 2026-04-29T19:24:35.902Z
Reserved: 2026-04-29T12:07:42.797Z
Link: CVE-2018-25303
No data.
Status : Deferred
Published: 2026-04-29T20:16:25.620
Modified: 2026-04-29T21:22:20.120
Link: CVE-2018-25303
No data.