
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2019-25318 is a stack-based buffer overflow vulnerability in AVS Audio Converter version 9.1.2.600, developed by AVS4You. The flaw allows attackers to execute arbitrary code by supplying a malicious payload in the output folder text input field, which overwrites stack memory when the 'Browse' button is clicked. The vulnerability was published on February 12, 2026, and carries a CVSS v3.1 base score of 8.8 (High) (Red Hat CVE).
The root cause is a stack-based buffer overflow (CWE-121) in AVS Audio Converter 9.1.2.600's handling of the output folder text input. When a user clicks the 'Browse' button, the application fails to properly validate or bound-check the length of the input string, allowing an attacker-controlled payload to overwrite adjacent stack memory. Exploitation requires user interaction — specifically, the victim must trigger the 'Browse' button action with a crafted input — but requires no privileges or authentication. The exploit can be weaponized to spawn a bind shell on TCP port 9999, providing the attacker with remote command execution (Red Hat CVE).
Successful exploitation results in high impact to confidentiality, integrity, and availability on the affected system. An attacker can achieve arbitrary code execution in the context of the application user, potentially establishing a bind shell on port 9999 for persistent remote access. The scope is limited to the local system running AVS Audio Converter, but the bind shell could enable lateral movement within a network if the compromised host has further access (Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.033%, indicating a low probability of exploitation in the near term. Exploitation requires user interaction, which somewhat limits opportunistic attack scenarios.
netstat or endpoint detection tools.cmd.exe, powershell.exe, or shell interpreters); new network listener processes associated with the AVS Audio Converter PID.No official patch from AVS4You has been confirmed as available for this vulnerability. Organizations and users running AVS Audio Converter 9.1.2.600 should restrict access to the application and avoid using it with untrusted input in the output folder field. Monitor systems for unexpected network connections on TCP port 9999. As a longer-term measure, consider replacing AVS Audio Converter with an alternative audio conversion tool with a stronger security track record until a vendor patch is released (Red Hat CVE).
Coverage of CVE-2019-25318 has been limited to automated CVE alert aggregators and security feeds, including RedPacketSecurity and VulDB, with no notable researcher commentary or vendor statements beyond the Red Hat CVE advisory page (Red Hat CVE). No significant community discussion or media coverage has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."