CRITICAL
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 - Buffer OverFlow
Published Feb 18, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.68%
Description
WMV to AVI MPEG DVD WMV Convertor 4.6.1217 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting the license name and license code fields. Attackers can craft a malicious payload of 6000 bytes to trigger a bind shell on port 4444 by exploiting a stack-based buffer overflow in the application's input handling.
Affected products
-
- Version 4.6.1217StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Alloksoft | WMV to AVI MPEG DVD WMV Convertor | n/a |
|
- 4.6.1217
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://www.alloksoft.com/ productNot ApplicableURL Repurposed
- https://www.alloksoft.com/wmv.htm productNot ApplicableURL Repurposed
- https://www.exploit-db.com/exploits/47563 exploitVDB Entry
- https://www.exploit-db.com/exploits/47568 exploitVDB Entry
- https://www.vulncheck.com/advisories/wmv-to-avi-mpeg-dvd-wmv-convertor-buffer-overflow third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://www.alloksoft.com/ | productNot ApplicableURL Repurposed | |
| https://www.alloksoft.com/wmv.htm | productNot ApplicableURL Repurposed | |
| https://www.exploit-db.com/exploits/47563 | exploitVDB Entry | |
| https://www.exploit-db.com/exploits/47568 | exploitVDB Entry | |
| https://www.vulncheck.com/advisories/wmv-to-avi-mpeg-dvd-wmv-convertor-buffer-overflow | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Feb 18, 2026
Updated Jul 15, 2026
Reserved Feb 13, 2026
Link CVE-2019-25362
CISA Vulnrichment
Updated Feb 19, 2026