Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious username string. Attackers can craft a payload containing junk data, SEH chain pointers, and shellcode that overwrites the SEH handler to redirect execution and run arbitrary commands like opening calc.exe.
History

Mon, 04 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Description Easy MPEG to DVD Burner 1.7.11 contains a structured exception handling (SEH) local buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious username string. Attackers can craft a payload containing junk data, SEH chain pointers, and shellcode that overwrites the SEH handler to redirect execution and run arbitrary commands like opening calc.exe.
Title Easy MPEG to DVD Burner 1.7.11 SEH Local Buffer Overflow
First Time appeared Ether Software
Ether Software easy Mpeg To Dvd Burner
Weaknesses CWE-120
CPEs cpe:2.3:a:ether_software:easy_mpeg_to_dvd_burner:1.7.11:*:*:*:*:*:*:*
Vendors & Products Ether Software
Ether Software easy Mpeg To Dvd Burner
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-04-29T19:24:34.531Z

Updated: 2026-05-04T18:23:21.844Z

Reserved: 2026-04-29T12:03:15.620Z

Link: CVE-2018-25301

cve-icon Vulnrichment

Updated: 2026-05-01T16:39:11.058Z

cve-icon NVD

Status : Deferred

Published: 2026-04-29T20:16:25.320

Modified: 2026-04-30T15:44:48.290

Link: CVE-2018-25301

cve-icon Redhat

No data.