CVE-2010-3124: Critical severity Videolan VLC Media Player vulnerability
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse wintab32.dll that is located in the same folder as a .mp3 file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-3124?
CVE-2010-3124 is classified as a medium severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2010-3124?
To fix CVE-2010-3124, update to VLC Media Player version 1.1.4 or later, which removes the vulnerable code.
What types of attacks can CVE-2010-3124 facilitate?
CVE-2010-3124 can facilitate DLL hijacking attacks, allowing local and potentially remote users to execute arbitrary code.
Which versions of VLC Media Player are affected by CVE-2010-3124?
Versions 1.1.3 and earlier, as well as several older versions, are affected by CVE-2010-3124.
Can CVE-2010-3124 be exploited remotely?
While primarily a local attack, there is a possibility for remote exploitation if a malicious MP3 file is accessed.