Description
Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.
Published: 2026-03-21
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability allows attackers to cause the Lyric Video Creator 2.1 application to crash when it processes a specially crafted MP3 file. The flaw arises from an oversized buffer used during decoding of the media metadata. An attacker can create a malformed MP3 and trigger a denial‑of‑service by using the Browse song feature, resulting in application termination and potential disruption of user workflow. The weakness aligns with CWE‑226, which involves an out‑of‑bounds write or buffer overflow that can lead to denial of service.

Affected Systems

This issue affects the Lyric Video Creator 2.1 product released by Lyricvideocreator. Only the 2.1 version is known to be vulnerable; newer releases are not listed as impacted. The product is typically installed on Windows desktop environments and used for editing lyric videos.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.7, indicating a high severity. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog, suggesting it is not currently being widely exploited. The attack requires the victim to open a malformed MP3 file in the application, making it a local or user‑initiated exploit. Although the impact is disruptive, the attack vector does not permit remote code execution or privilege escalation. Nevertheless, any organization that relies on Lyric Video Creator 2.1 should treat this as a high‑risk issue until a patch is applied.

Generated by OpenCVE AI on March 21, 2026 at 14:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available update from Lyricvideocreator to patch Lyric Video Creator 2.1.
  • Avoid opening MP3 files from untrusted sources.
  • If an update is not available, consider disabling the Browse song function or restricting use of the application to trusted files.

Generated by OpenCVE AI on March 21, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:lyricvideocreator:lyric_video_creator:2.1:*:*:*:*:*:*:*

Mon, 23 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 23 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Lyricvideocreator
Lyricvideocreator lyric Video Creator
Vendors & Products Lyricvideocreator
Lyricvideocreator lyric Video Creator

Sat, 21 Mar 2026 13:00:00 +0000

Type Values Removed Values Added
Description Lyric Video Creator 2.1 contains a denial of service vulnerability that allows attackers to crash the application by processing malformed MP3 files. Attackers can create a crafted MP3 file with an oversized buffer and trigger the crash by opening the file through the Browse song functionality.
Title Lyric Video Creator 2.1 Denial of Service via MP3 File
Weaknesses CWE-226
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lyricvideocreator Lyric Video Creator
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-03-23T15:39:52.746Z

Reserved: 2026-03-21T12:31:26.076Z

Link: CVE-2019-25560

cve-icon Vulnrichment

Updated: 2026-03-23T15:39:48.366Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-21T13:16:18.957

Modified: 2026-04-16T18:02:42.237

Link: CVE-2019-25560

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-25T14:47:23Z

Weaknesses