Vulnerability Description
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Videolan | Vlc Media Player | < 3.0.19 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://www.videolan.org/security/sb-vlc3019.htmlVendor Advisory
- https://www.videolan.org/security/sb-vlc3019.htmlVendor Advisory
FAQ
What is CVE-2023-46814?
CVE-2023-46814 is a vulnerability with a CVSS score of 7.8 (HIGH). A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable...
How severe is CVE-2023-46814?
CVE-2023-46814 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-46814?
Check the references section above for vendor advisories and patch information. Affected products include: Videolan Vlc Media Player, Microsoft Windows.