A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
2023-11-22T05:15:07.837
2024-11-21T08:29:21.657
Modified
CVSSv3.1: 7.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | videolan | vlc_media_player | < 3.0.19 | Yes |
Operating System | microsoft | windows | - | No |