Executive brief
Allok Fast AVI MPEG Splitter is a Windows utility used for cutting and splitting video files. A security flaw in the software's registration process allows an attacker with local access to the computer to take full control of the application. By entering a specially crafted, overly long string into the license name field, an attacker can crash the program and execute malicious code with the same permissions as the logged-in user.
Technical details
A stack-based buffer overflow (CWE-121) exists in Allok Fast AVI MPEG Splitter version 1.2. The vulnerability is triggered when the application processes an excessively long string in the 'License Name' field during registration. An attacker can exploit this by providing a payload consisting of approximately 780 bytes of padding followed by a Next SEH (nSEH) record, an SEH handler overwrite, and shellcode. Because the application does not properly validate the length of the input before copying it to a fixed-size stack buffer, the SEH chain is overwritten, allowing for arbitrary code execution with the privileges of the application. This is a local exploit requiring the attacker to have the ability to input data into the registration interface.
Affected products
- Allok Soft Fast AVI MPEG Splitter 1.2
Timeline
- 2018-03-06: disclosed: Vulnerability discovered and exploit code authored
- 2018-03-26: other: Exploit published to Exploit-DB
- 2026-05-17: advisory: CVE formally published and added to NVD dataset