Junglewise Threat Intelligence

CVE-2018-25383: Cleanersoft Free MP3 CD Ripper stack overflow in WMA processing

CVE-2018-25383 · Severity: high · CVSS 8.4 · Published 2026-05-29

Executive brief

Free MP3 CD Ripper is a Windows utility used to extract audio from CDs and convert audio files between different formats. A security flaw in how the application handles WMA files allows an attacker to take control of a user's computer if they can trick the user into opening a specially crafted, malicious audio file. This could lead to the unauthorized installation of software, data theft, or full system compromise.

Technical details

A stack-based buffer overflow (CWE-121) exists in Free MP3 CD Ripper version 2.8 and potentially earlier versions within the WMA file processing logic of the 'Convert' function. By crafting a malicious WMA file, a local attacker can trigger an overflow that overwrites structured exception handlers (SEH). This allows the attacker to bypass Data Execution Prevention (DEP) using Return-Oriented Programming (ROP) gadgets and execute arbitrary shellcode. The attack requires the victim to manually load the malicious file into the application's conversion utility. No official patch is currently documented for this legacy software.

Affected products

  • Cleanersoft Software Free MP3 CD Ripper 2.8 and earlier

Timeline

  • 2018-10-08: other: Exploit-DB proof of concept published
  • 2026-05-29: advisory: NVD/VulnCheck advisory published

References