CVE-2019-25318: AVS4YOU Avs Audio Converter
High severity, CVSS 8.8. EPSS: 0.3% chance of exploitation in the next 30 days.
AVS Audio Converter 9.1.2.600 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by manipulating the output folder text input. Attackers can craft a malicious payload that overwrites stack memory and triggers a bind shell on port 9999 when the 'Browse' button is clicked.
Affected products
- AVS4YOU Avs Audio Converter: version 9.1.2.600 only
Published 2026-02-12. Last modified 2026-06-17.