Junglewise Threat Intelligence

CVE-2018-25355: Audiograbber local buffer overflow in Interpret or Album fields

CVE-2018-25355 · Severity: high · CVSS 8.4 · Published 2026-05-23

Executive brief

Audiograbber is a Windows application used to extract audio from CDs and convert it into digital formats like MP3. A security flaw in the software allows a local attacker to take full control of the computer by providing specially crafted text in the "Interpret" or "Album" information fields. This could lead to the execution of malicious code, potentially resulting in data theft or a complete system compromise.

Technical details

A classic stack-based buffer overflow (CWE-120) exists in Audiograbber version 1.83 and potentially earlier. The vulnerability is triggered when the application processes overly long strings in the 'Interpret' (Artist) or 'Album' metadata fields. An attacker can exploit this by overwriting Structured Exception Handler (SEH) pointers. By crafting a malicious input that triggers an exception, the attacker can redirect the execution flow to injected shellcode. This is a local exploit requiring the attacker to provide a malicious file or input string to the application; once triggered, the shellcode executes with the privileges of the logged-in user.

Affected products

  • Audiograbber Audiograbber 1.83 and earlier

Timeline

  • 2018-06-16: other: Exploit code originally authored by Dennis Herrmann
  • 2026-05-23: advisory: Vulnerability details published and CVE assigned

References