vendor:
VLC Player
by:
Jean Pascal Pereira
7.5
CVSS
HIGH
Arbitrary Code Execution
119
CWE
Product Name: VLC Player
Affected Version From: 2.0.3
Affected Version To: 2.0.3
Patch Exists: NO
Related CWE: CVE-XXXX-XXXX
CPE: a:videolan:vlc:2.0.3
Platforms Tested: Windows
VLC Player 2.0.3 <= ReadAV Arbitrary Code Execution
This exploit allows an attacker to execute arbitrary code in VLC Player version 2.0.3 or earlier. By crafting a malicious PNG file, an attacker can trigger a buffer overflow vulnerability in the VLC Player, leading to the execution of arbitrary code.
Mitigation:
Update VLC Player to the latest version to mitigate this vulnerability. Do not open or download files from untrusted sources.