Executive brief
Allok AVI DivX MPEG to DVD Converter is a software utility used to convert video files into DVD-compatible formats. A security flaw in the software's registration process allows an attacker with local access to the computer to take full control of the system. By pasting a specially crafted string into the license name field, an attacker can execute malicious code, potentially leading to data theft or complete system compromise.
Technical details
A classic buffer overflow (CWE-120) exists in Allok AVI DivX MPEG to DVD Converter version 2.6.1217. The vulnerability is located in the 'License Name' input field, which fails to properly validate the length of user-supplied strings. An attacker can exploit this by providing a long string that overwrites the Structured Exception Handler (SEH) chain. By crafting a payload with a specific offset, a 'pop-pop-ret' sequence (found in SkinMagic.dll), and shellcode, an attacker can redirect execution flow to achieve arbitrary code execution. This is a local attack requiring the attacker to manually paste the malicious string into the application's registration interface.
Affected products
- Allok AVI DivX MPEG to DVD Converter 2.6.1217 and earlier
Timeline
- 2018-03-27: disclosed: Original exploit code authored by wetw0rk
- 2026-05-17: advisory: CVE record published and NVD dataset updated