Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

VLC Media Player < 1.1.4 Patch Subversion Arbitrary DLL Injection Code Execution (deprecated)

Medium

Synopsis

The remote host contains an application that allows arbitrary code execution.

Description

The remote host contains VLC player, a multi-media application.

Versions of VLC media player earlier than 1.1.4 are potentially affected by a code execution vulnerability. The application insecurely looks in its current working directory when resolving DLL dependencies, such as for 'wintab32.dll'. If a malicious DLL with the same name as a required DLL is located in the application's current working directory, the malicious DLL will be loaded.

Solution

Upgrade to VLC Media Player version 1.1.4 or later.