CVE-2020-37184: Allok Soft Allok Video Converter
Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.
Allok Video Converter 4.6.1217 contains a stack overflow vulnerability in the License Name input field that allows attackers to execute arbitrary code. Attackers can craft a specially designed payload to overwrite SEH handlers and execute system commands by injecting malicious bytecode into the input field.
Affected products
- Allok Soft Allok Video Converter: version 4.6.1217 only
Published 2026-02-11. Last modified 2026-06-17.