Description
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-50980 | A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM. |
References
| Link | Providers |
|---|---|
| https://www.videolan.org/security/sb-vlc3019.html |
|
History
Thu, 26 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:videolan:vlc_media_player:-:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-29T19:59:01.503Z
Reserved: 2023-10-27T00:00:00.000Z
Link: CVE-2023-46814
Updated: 2024-08-02T20:53:21.940Z
Status : Modified
Published: 2023-11-22T05:15:07.837
Modified: 2024-11-21T08:29:21.657
Link: CVE-2023-46814
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD