VLC Media Player has an unpatched vulnerability that allows remote code execution (update)

Posted on Monday, July 22 2019 @ 12:30 CEST by Thomas De Maesschalck
VLC logo
UPDATE: July 25, 2019:
False alarm, the VLC developers reveal on Twitter that the vulnerability recently "found" in the media player no longer exists. The tweet mentions this was a flaw in a third-party library, and that it got fixed 16 months ago. Furthermore, VLC is safe since version 3.0.3.






If you use VLC Media Player, be aware that the media player suffers from a security vulnerability that could allow remote code execution. By using a specially crafted MP4 media file, attackers can trigger a buffer overflow and do all sorts of nefarious tasks on your computer.

The bug is present in all version of VLC Media Player and there is no fix. The VLC Media Player developers have been working on a fix since late June, a recent update indicates the patch is about 60 percent ready.

In the meantime, users better be careful about opening media files from untrusted sources. It's unknown if this bug is actively exploited in the wild.


About the Author

Thomas De Maesschalck

Thomas has been messing with computer since early childhood and firmly believes the Internet is the best thing since sliced bread. Enjoys playing with new tech, is fascinated by science, and passionate about financial markets. When not behind a computer, he can be found with running shoes on or lifting heavy weights in the weight room.



Loading Comments