First published: Wed Nov 22 2023(Updated: )
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Videolan Vlc Media Player | <3.0.19 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46814 is a binary hijacking vulnerability in the VideoLAN VLC media player before version 3.0.19 on Windows.
CVE-2023-46814 has a severity rating of 7.8 out of 10, indicating a high severity.
CVE-2023-46814 allows standard users to gain arbitrary code execution as SYSTEM by exploiting a binary hijacking vulnerability in the VideoLAN VLC media player uninstaller on Windows.
No, Microsoft Windows is not affected by CVE-2023-46814.
To fix CVE-2023-46814, users should update their VideoLAN VLC media player to version 3.0.19 or later.