Vulnerability record · CVE-2015-7243 · published 18 September 2015
CVE-2015-7243: Boxoft WAV to MP3 Converter buffer overflow via crafted WAV file
Boxoft · Boxoft Wav To Mp3 Converter
Boxoft WAV to MP3 Converter contains a memory buffer overflow (CWE-119) that is triggered when the application processes a crafted WAV file. A remote attacker can cause a denial of service and possibly execute arbitrary code. The flaw matters because the tool is designed to open untrusted media files, so a malicious WAV can compromise the host running the converter.
Description
Buffer overflow in Boxoft WAV to MP3 Converter allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted WAV file.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but the flaw requires a user to open a crafted file and is not known to be exploited in the wild per KEV.
What it is
Boxoft WAV to MP3 Converter contains a memory buffer overflow (CWE-119) that is triggered when the application processes a crafted WAV file. A remote attacker can cause a denial of service and possibly execute arbitrary code. The flaw matters because the tool is designed to open untrusted media files, so a malicious WAV can compromise the host running the converter.
Impact
An attacker can crash the converter and potentially achieve arbitrary code execution in the context of the user running the application. Successful exploitation could lead to full compromise of that user's session and data.
Attack surface
The attack is reached by supplying a crafted WAV file to the converter, either directly or by convincing a user to open it. No authentication is required per the CVSS vector (AV:N/AC:L/Au:N), but user interaction is implied since a file must be opened in the application.
Exploitation
Public exploit code exists in Packet Storm and Exploit-DB references, and EPSS is high (0.58272, 99th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.
What to do
- Upgrade to a patched or supported version of Boxoft WAV to MP3 Converter, or replace it with a maintained converter if no fix is available.
- Block or sandbox the converter so it cannot process untrusted WAV files from email, downloads, or removable media.
- Enforce least privilege for users who run the converter to limit the impact of code execution.
- Scan incoming WAV files with content inspection or file-type validation before opening them in the converter.
Detection
- Monitor for crashes or abnormal process termination of the WAV to MP3 converter, especially after opening externally sourced WAV files.
- Look for child processes or network connections spawned by the converter, which would indicate code execution beyond normal conversion behavior.
- Track execution of the converter against files originating from email attachments, downloads, or removable media.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7243 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7243), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.