Executive brief
River Past Video Cleaner is a software tool used for converting and processing video files. A security flaw allows a local user to take full control of the computer by entering a specially crafted, overly long text string into the application's settings. This could lead to unauthorized software installation, data theft, or complete system compromise.
Technical details
A stack-based buffer overflow exists in River Past Video Cleaner 7.6.3 within the 'Lame_enc.dll' input field under the application options. The vulnerability is a Structured Exception Handler (SEH) overflow, where an attacker can provide a malicious string (approximately 280 bytes of padding followed by an SEH override) to redirect execution flow. By triggering an exception after overwriting the SEH record, a local attacker can execute arbitrary shellcode with the privileges of the application. This is a local attack requiring the ability to input data into the application's configuration interface.
Affected products
- River Past Video Cleaner 7.6.3
Timeline
- 2019-02-09: disclosed: Original exploit author discovery
- 2019-02-11: other: Exploit published to Exploit-DB
- 2026-04-05: advisory: NVD/VulnCheck advisory published