VLC Media Player Hit by Critical Security Flaw That Allows Remote Code Execution, VideoLAN Currently Working on a Patch

VideoLAN denies that the proof-of-concept video can crash the media player.

Advertisement
By Nadeem Sarwar | Updated: 24 July 2019 15:01 IST
Highlights
  • The security flaw is classified as critical with a risk rating of 9.8/10
  • Only Windows, Linux, and UNIX versions of VLC are affected
  • There is no word when the patch will be released

A patch is currently under development and is 60 percent complete

VLC - the popular open-source media player which recently clocked the 3 billion downloads milestone – is in the news again, but for the wrong reasons. A potentially serious security flaw has been discovered in the media player's PC version that leaves the door open for hackers to execute malicious code. The flaw in VLC can reportedly be exploited for launching a denial of service attack, corrupting files, stealing data, and do a lot more. However, there have been no reports so far of the flaw being exploited and a patch is currently under development.

The security flaw, which was reported by CERT-Bund, has been discovered in version 3.0.7.1 of VLC and currently has a NIST threat score of 9.8 out of 10, classifying it as critical. Labelled CVE-2019-13615 in the National Vulnerability Database, the latest VLC security flaw can be exploited by baiting users into playing a malicious MKV video file. Thus, while some reports urge users to uninstall VLC until the patch is rolled out, it's likely safe just not playing an untrusted MKV format file.

Advertisement

A report by The Register claims that a proof-of-concept video exploiting the vulnerability crashes the VLC media player. However, developer comments on the official VideoLAN bug tracking forum state that the VLC crash result cannot be reproduced in large, and is only functional when the ‘Loop One” feature is enabled on VLC's Windows version.

As for the risks, the flaw can be exploited by a malicious party to remotely execute a harmful code and do damage ranging from data theft to service disruption. So far, there have been no reports of the VLC security flaw being misused. Another thing to note here is that only Windows, UNIX, and Linux versions of VLC are affected by the vulnerability, and not its macOS client. VideoLAN said in a tweet that it was unhappy it wasn't contacted before the flaw was published by vulnerability trackers.

Advertisement

VideoLAN has acknowledged the issue and is currently working on a patch that is said to be 60 percent complete. Interestingly, the company behind VLC media player has denied that the bug can even be reproduced to crash VLC media player at all, and the same message has been relayed by a couple of VLC developers as well. However, we recommend readers to temporarily switch to another media player and come back to VLC after VideoLAN has released a patch to fix the security flaw.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: VLC, VLC Security Flaw
Advertisement

Related Stories

Popular Mobile Brands
  1. Here's When the Redmi 15A 5G Will Be Launched in India
  2. Lenovo Legion Y700 Gen 5 Launched With Snapdragon 8 Elite Gen 5 SoC, 9,000mAh Battery
  3. Nothing Phone 4a Pro Review: A Big Leap
  4. OnePlus Nord 6 Specifications Surface as Tipster Leaks Photo of Retail Box
  5. Samsung Galaxy Forever Offers Easy Upgrade, Return Option in India
  6. NDTV Gadgets360 Awards 2026: Check out the Nominations for India's Most Trusted Award Show
  7. Xiaomi Watch S5 With a 1.48-Inch AMOLED Display Arrives at This Price
  8. OTT Releases This Week: Border 2, Peaky Blinders: The Immortal Man, Chiraiya, and More
  9. Oppo K14 5G With 7,000mAh Battery Goes on Sale in India: See Price, Offers
  10. Smartphone Makers Reportedly Oppose Preinstalled Aadhaar App on Phones
  1. Anthropic Study Finds People Don’t Really Want AI for Creative Work
  2. Bitcoin Trades Near $71,000 as Crypto Market Weathers Ongoing Macroeconomic Pressures
  3. Redmi 15A 5G India Launch Date Announced; Design and Specifications Teased
  4. World Happiness Report 2026: Heavy Social Media Use Linked to Lower Life Satisfaction Among Teenagers
  5. Oppo K14 5G With 7,000mAh Battery, 50-Megapixel Camera Goes on Sale in India: Price, Offers
  6. Oppo Find X9 Ultra, Find X9s Appearance on SIRIM Certification Database Signals Imminent Launch
  7. OnePlus Nord 6 Retail Box Revealed in Leaked Image as Tipster Shares Key Specifications and Launch Timeline
  8. Canada Revokes Registrations of Crypto Firms in Crackdown on Compliance Failures
  9. OpenAI Has Reportedly Started Working on Sora Integration in ChatGPT
  10. Flagship Memory Configurations on Android Phones Now Cost More Than Snapdragon Chips, Tipster Claims
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.