Impact
An out‑the BaseSplitterFile::Read function of the Aleksoid1978 MPC‑BE media player causes an access violation when a crafted MP4 file is processed, leading to a crash of the player. The crash terminates playback, resulting in a denial of service. This only changes the integrity of the media playback process and is a memory safety error classified as CWE‑119.
Affected Systems
The flaw exists in all builds of MPC‑BE preceding commit 4341cb3. Users running older source‑code or compiled editions before this commit are potentially at risk. No specific release numbers are cited, so every build prior to the mentioned commit should be considered vulnerable.
Risk and Exploitability
The attacker simply needs to supply a malicious MP4 file and have the victim open it with the vulnerable player; no remote code execution is required. Based on the description, the attack vector is inferred to be local or network delivery of a crafted MP4 file to a vulnerable user. The CVSS score of 5.5 indicates moderate severity for environments that rely on continuous media playback. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, implying a low likelihood of exploitation. However, in critical or embedded systems where media playback is essential, the denial of service could be disruptive.
OpenCVE Enrichment