CVE-2018-11529

VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV...

Basic Information

CVE State
PUBLISHED
Reserved Date
May 29, 2018
Published Date
July 11, 2018
Last Updated
August 05, 2024
Vendor
VideoLAN
Product
VLC media player
Description
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result in denial of service conditions.
Tags
metasploit

CVSS Scores

CVSS v3.0

8.0 - HIGH

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS v2.0

6.8

Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Exploit Status

Exploited in the Wild
Yes (2018-07-11 16:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2018-07-11 16:00:00 UTC

Recent Mentions

ABB Ability Camera Connect

Source: All CISA Advisories • Published: 2026-05-26 12:00:00 UTC

View CSAF Summary ABB is aware of public reports of vulnerabilities in a 3rd party component VLC media player Version 2.2.4 which was delivered together with the installation package of Camera Connect Version 1.5.0.14 and below. An update is available that resolves a privately reported outdated 3rd party component with vulnerabilities in the product versions listed as affected in this advisory. An attacker who successfully exploited any of these vulnerabilities in the 3rd party component could potentially compromise the system in different ways. The following versions of ABB Ability Camera Connect are affected: Ability Camera Connect vers:intdot/<=1.5.0.14, 1.5.0.15 CVSS Vendor Equipment Vulnerabilities v3 9.8 ABB ABB Ability Camera Connect Heap-based Buffer Overflow, Integer Underflow (Wrap or Wraparound), Out-of-bounds Write, Uncontrolled Search Path Element, Integer Overflow or Wraparound, Off-by-one Error, Out-of-bounds Read, Double Free, Improper Restriction of Operations within the Bounds of a Memory Buffer, Use After Free Background Critical Infrastructure Sectors: Chemical, Commercial Facilities, Communications, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2024-46461 VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's privileges. View CVE Details Affected Products ABB Ability Camera Connect Vendor:ABB Product Version:ABB Ability Camera Connect <=1.5.0.14 Product Status:fixed, known_affected Remediations MitigationThe VLC-based component operates solely within completely isolated environments without internet access or any connectivity to external...

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

vlc_mkv

Type: metasploit • Created: Unknown

Metasploit module for CVE-2018-11529

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Metasploit