CVE-2023-46814: High severity vlc media player vulnerability
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46814?
CVE-2023-46814 is a binary hijacking vulnerability in the VideoLAN VLC media player before version 3.0.19 on Windows.
How severe is CVE-2023-46814?
CVE-2023-46814 has a severity rating of 7.8 out of 10, indicating a high severity.
How does CVE-2023-46814 work?
CVE-2023-46814 allows standard users to gain arbitrary code execution as SYSTEM by exploiting a binary hijacking vulnerability in the VideoLAN VLC media player uninstaller on Windows.
Is Microsoft Windows affected by CVE-2023-46814?
No, Microsoft Windows is not affected by CVE-2023-46814.
How can I fix CVE-2023-46814?
To fix CVE-2023-46814, users should update their VideoLAN VLC media player to version 3.0.19 or later.