CVE-2018-25383 - CVE House
Back to Database
Status published High CVE-2018-25383

Free MP3 CD Ripper 2.8 Buffer Overflow SEH DEP Bypass

Vulnerability Description

Free MP3 CD Ripper 2.8 contains a stack-based buffer overflow vulnerability in WMA file processing that allows local attackers to bypass DEP protection via structured exception handling manipulation. Attackers can craft a malicious WMA file that triggers the overflow when loaded through the Convert function, enabling execution of arbitrary code through ROP chain gadgets and shellcode injection.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-25383

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Matteo Malvica

Affected Vendor

Commentcamarche

View all reports →

Affected Software

Free MP3 CD Ripper
Vulnerable Versions:
2.8

Timeline

Official Publish: May 29th, 2026
Last Modified: May 29th, 2026
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)