Thursday, April 18, 2024

Critical Vulnerabilities in VLC Player Let Hacker Stream Untrusted Video To Hack Your PC – 200 Million Computers at Risk

Its time for hackers to hack your PC using malformed video file, yes, critical vulnerabilities in VLC media Player let attackers load specially crafted video files in the vulnerable system to execute the arbitrary code.

VideoLAN released a security update for VLC Media player with the fixes for two vulnerabilities that allow attackers to execute untrusted video file on the system running with vulnerable VLC media player.

The VLC media player is an open source cross-platform and streaming media server developed by the VideoLAN project.

VLC Player downloaded over more than 200 million users around the globe and running in hundreds of millions of major operating system including Windows, iOS, Android, Mac.

There are 2 vulnerability uncovered and reported by Symeon Paraschoudis from pentest partners and zhangyang from Hackerone.

First, A buffer overflow vulnerability (CVE-2019-5439) that resides in ReadFrame (demux/avi/avi.c) allows a remote user can create some specially crafted avi or mkv files that will trigger a heap buffer overflow load into a targeted system.

Second high severity (CVE-2019-12874) MKV double free vulnerability in zlib_decompress_extra() (demux/mkv/utils.cpp) can be triggered while parsing a malformed mkv file.

Successfully execution of malformed file in the targeted system leads to crash the VLC player and eventually attackers execute the arbitrary code with the context of privileged users.

In order to exploit the vulnerability, targetted users require to explicitly open a specially crafted file or stream which can be initiated by attackers via from malicious sites.

According to VideoLAN Security Advisory, “The user should refrain from opening files from untrusted third parties or accessing untrusted remote sites (or disable the VLC browser plugins), until the patch is applied. “

Patch has been applied for both vulnerabilities in VLC player 3.0.7 update. All the users urged to update the VLC player 3.0.7 immediately to prevent your system from hackers to exploit this vulnerability.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates also you can take the Best Cybersecurity courses online to keep your self-updated.

Also Read:

200 Million Downloaded video players including VLC Player are vulnerable to Malicious subtitles Attack

Critical Code Execution Vulnerability Found in Libraries Used By VLC and Other Media Players

Website

Latest articles

Xiid SealedTunnel: Unfazed by Yet Another Critical Firewall Vulnerability (CVE-2024-3400)

In the wake of the recent disclosure of a critical vulnerability (CVE-2024-3400) affecting a...

Cerber Linux Ransomware Exploits Atlassian Servers to Take Full Control

Security researchers at Cado Security Labs have uncovered a new variant of the Cerber...

FGVulDet – New Vulnerability Detector to Analyze Source Code

Detecting source code vulnerabilities aims to protect software systems from attacks by identifying inherent...

North Korean Hackers Abuse DMARC To Legitimize Their Emails

DMARC is targeted by hackers as this serves to act as a preventative measure...

L00KUPRU Ransomware Attackers discovered in the wild

A new variant of the Xorist ransomware, dubbed L00KUPRU, has been discovered in the...

Oracle Releases Biggest Security Update in 2024 – 372 Vulnerabilities Are Fixed – Update Now!

Oracle has released its April 2024 Critical Patch Update (CPU), addressing 372 security vulnerabilities...

Outlook Login Panel Themed Phishing Attack Evaded All Antivirus Detections

Cybersecurity researchers have uncovered a new phishing attack that has bypassed all antivirus detections.The...
Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

WAAP/WAF ROI Analysis

Mastering WAAP/WAF ROI Analysis

As the importance of compliance and safeguarding critical websites and APIs grows, Web Application and API Protection (WAAP) solutions play an integral role.
Key takeaways include:

  • Pricing models
  • Cost Estimation
  • ROI Calculation

Related Articles