vendor:
VLC Media Player
by:
Kevin Finisterre
7.5
CVSS
HIGH
Arbitrary Code Execution
CWE
Product Name: VLC Media Player
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: OSX
2007
VLC Media Player Arbitrary Code Execution Vulnerability
This exploit creates a malicious .m3u file that causes VLC Player for OSX to execute arbitrary code. It uses a bind shell to achieve this.