Vulnerability record · CVE-2011-5003 · published 25 December 2011
CVE-2011-5003: Avid Media Composer Phonetic Indexer stack buffer overflow
Avid · Media Composer
The Phonetic Indexer service (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier contains a stack-based buffer overflow reachable through a long request sent to TCP port 4659. Because the service is network-facing and the flaw allows code execution, an unauthenticated attacker on a reachable network can compromise the host.
Description
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier allows remote attackers to execute arbitrary code via a long request to TCP port 4659.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10, a public exploit, and very high EPSS probability.
What it is
The Phonetic Indexer service (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier contains a stack-based buffer overflow reachable through a long request sent to TCP port 4659. Because the service is network-facing and the flaw allows code execution, an unauthenticated attacker on a reachable network can compromise the host.
Impact
An attacker can execute arbitrary code with the privileges of the Phonetic Indexer process, giving full control of the affected workstation or server.
Attack surface
Reached over the network via TCP port 4659; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but a public Exploit-DB entry (18183) exists and EPSS is high (0.624, 99th percentile), so exploitation is feasible and likely.
What to do
- Upgrade Avid Media Composer to a version later than 5.5.3, or apply the vendor fix referenced in the Secunia advisory.
- If the Phonetic Indexer is not needed, stop and disable the AvidPhoneticIndexer.exe service.
- Block or restrict inbound TCP port 4659 at host and network firewalls to trusted hosts only.
- Isolate Media Composer editing systems on a segmented network away from general user and internet-facing segments.
Detection
- Monitor for crashes or restarts of AvidPhoneticIndexer.exe and for Windows application error events referencing it.
- Alert on inbound connections to TCP port 4659 from hosts outside the expected editing subnet.
- Hunt for unusually long or malformed payloads to port 4659 in network flow or IDS logs.
- Check for unexpected child processes or command shells spawned by AvidPhoneticIndexer.exe.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-5003 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-5003), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.