PT-2026-28249 · Boxoft · Wav To Wma Converter

Published

2026-03-26

·

Updated

2026-03-26

·

CVE-2018-25212

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code execution on Windows systems.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2018-25212

Affected Products

Wav To Wma Converter