Junglewise Threat Intelligence

CVE-2019-25670: River Past Video Cleaner SEH buffer overflow in Lame_enc.dll field

CVE-2019-25670 · Severity: high · CVSS 8.4 · Published 2026-04-05

Executive brief

River Past Video Cleaner is a software tool used for converting and processing video files. A security flaw allows a local user to take full control of the computer by entering a specially crafted, overly long text string into the application's settings. This could lead to unauthorized software installation, data theft, or complete system compromise.

Technical details

A stack-based buffer overflow exists in River Past Video Cleaner 7.6.3 within the 'Lame_enc.dll' input field under the application options. The vulnerability is a Structured Exception Handler (SEH) overflow, where an attacker can provide a malicious string (approximately 280 bytes of padding followed by an SEH override) to redirect execution flow. By triggering an exception after overwriting the SEH record, a local attacker can execute arbitrary shellcode with the privileges of the application. This is a local attack requiring the ability to input data into the application's configuration interface.

Affected products

  • River Past Video Cleaner 7.6.3

Timeline

  • 2019-02-09: disclosed: Original exploit author discovery
  • 2019-02-11: other: Exploit published to Exploit-DB
  • 2026-04-05: advisory: NVD/VulnCheck advisory published

References