CVE-2018-25212 HIGH

CVE-2018-25212: Boxoft wav-wma Converter 1.0 Local Buffer Overflow SEH

Vendor Boxoft
Product WAV to WMA Converter
Weakness CWE-787
Published March 26, 2026
Last update March 28, 2026

CVSS base score

8.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Boxoft wav-wma Converter 1.0 contains a local buffer overflow vulnerability in structured exception handling that allows attackers to execute arbitrary code by crafting malicious WAV files. Attackers can create a specially crafted WAV file with excessive data and ROP gadgets to overwrite the SEH chain and achieve code execution on Windows systems.

Key dates

02Disclosure timeline

March 26, 2026 CVE published
March 28, 2026 Record updated