Thursday, May 15, 2025
HomeCVE/vulnerabilityCritical Vulnerabilities in VLC Player Let Hacker Stream Untrusted Video To Hack...

Critical Vulnerabilities in VLC Player Let Hacker Stream Untrusted Video To Hack Your PC – 200 Million Computers at Risk

Published on

SIEM as a Service

Follow Us on Google News

Its time for hackers to hack your PC using malformed video file, yes, critical vulnerabilities in VLC media Player let attackers load specially crafted video files in the vulnerable system to execute the arbitrary code.

VideoLAN released a security update for VLC Media player with the fixes for two vulnerabilities that allow attackers to execute untrusted video file on the system running with vulnerable VLC media player.

The VLC media player is an open source cross-platform and streaming media server developed by the VideoLAN project.

- Advertisement - Google News

VLC Player downloaded over more than 200 million users around the globe and running in hundreds of millions of major operating system including Windows, iOS, Android, Mac.

There are 2 vulnerability uncovered and reported by Symeon Paraschoudis from pentest partners and zhangyang from Hackerone.

First, A buffer overflow vulnerability (CVE-2019-5439) that resides in ReadFrame (demux/avi/avi.c) allows a remote user can create some specially crafted avi or mkv files that will trigger a heap buffer overflow load into a targeted system.

Second high severity (CVE-2019-12874) MKV double free vulnerability in zlib_decompress_extra() (demux/mkv/utils.cpp) can be triggered while parsing a malformed mkv file.

Successfully execution of malformed file in the targeted system leads to crash the VLC player and eventually attackers execute the arbitrary code with the context of privileged users.

In order to exploit the vulnerability, targetted users require to explicitly open a specially crafted file or stream which can be initiated by attackers via from malicious sites.

According to VideoLAN Security Advisory, “The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied. “

Patch has been applied for both vulnerabilities in VLC player 3.0.7 update. All the users urged to update the VLC player 3.0.7 immediately to prevent your system from hackers to exploit this vulnerability.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

200 Million Downloaded video players including VLC Player are vulnerable to Malicious subtitles Attack

Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

Threat Actors Leverage Weaponized HTML Files to Deliver Horabot Malware

A recent discovery by FortiGuard Labs has unveiled a cunning phishing campaign orchestrated by...

TA406 Hackers Target Government Entities to Steal Login Credentials

The North Korean state-sponsored threat actor TA406, also tracked as Opal Sleet and Konni,...

Google Threat Intelligence Releases Actionable Threat Hunting Technique for Malicious .desktop Files

Google Threat Intelligence has unveiled a series of sophisticated threat hunting techniques to detect...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Google Chrome Zero-Day Vulnerability (CVE-2025-4664) Actively Exploited in The Wild

Google has rolled out a fresh Stable Channel update for the Chrome browser across...

New Adobe Photoshop Vulnerability Enables Arbitrary Code Execution

Adobe has released critical security updates addressing three high-severity vulnerabilities (CVE-2025-30324, CVE-2025-30325, CVE-2025-30326) in...

Severe Adobe Illustrator Flaw Allows Remote Code Execution

Adobe has issued an urgent security update for its widely used graphic design software,...