PT-2026-46205 · Allplayer · Allplayer

·

CVE-2019-25735

·

Published

2026-06-04

·

Updated

2026-06-04

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AllPlayer version 7.4
Description A local buffer overflow exists in the way URLs are handled. An attacker can overwrite structured exception handling (SEH) pointers—a mechanism used to handle software errors—by providing an excessively long URL string. By crafting a malicious URL and pasting it into the Open URL dialog, an attacker can trigger SEH-based code execution to run arbitrary commands with user privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25735

Affected Products

Allplayer