VLC Media Player identified with Critical Security Flaw, Should you uninstall?

Main Image
  • Like
  • Comment
  • Share

Update: VideoLAN tweets that VLC is no more vulnerable as the issue had been fixed more than 16 months ago. So, as users, all you need to do is update the application to its latest version.

VLC is the go-to media player software for Windows and it has a fair share of downloads on the Android and iOS mobile platforms. So, your PC or phone might also have it installed. A German security agency has discovered a potentially critical flaw. The attack is alleged to start by playing a malicious MKV video file. Attackers can then apparently hijack your device and access the files.

The VLC security flaw: What does it mean?

VLC security flaw

VLC is a popular open-source media player from a french company called VideoLAN. It recently crossed 3 billion downloads, which in itself is a testament to its fame. However, now the application is blamed with a “critical” vulnerability score of 9.8 out of 10 by CERT-Bund, the aforementioned German security agency. It is published in and as CVE-2019-13615.

ALSO READ: Netflix Mobile-Only Plan for India launched at Rs. 199 per Month: How is it different from the basic plan?

If you’re wondering, the issue is in the PC (Windows, Unix, and Linux) version, which opens a backdoor for hackers to push malicious attack. This is called Remote Code Execution, which could result in a DDoS (denial of service) attack, file corruption, data theft, and more.

VLC users (PC): What can you do?

VLC security flaw
Source: VideoLAN

You’re advised to stay away from malformed MKV files from the internet, until the alleged flaw is patched and we are sure of no problems, whatsoever. First of all, don’t download from any shady websites. And even if something gets flushed into your Downloads folder, don’t run it. A pro tip would be to avoid pirate videos (especially MKV format) from Torrents and other such sources.

ALSO READ: Realme X FAQ – All Questions Answered

Further, you should always keep all software (VLC included) up-to-date. Ensure, VLC is updated with its latest libraries. Or you may try VLC alternatives like KMPlayer or Media Player Classic. That’s all for now.

What is VLC’s response?

The Good News is the problem isn’t yet exploited. VLC is also aware of the situation and is working around a patch. The patch is reportedly 60-percent ready. But until then many systems are vulnerable.

The VLC developers claim the issue isn’t as serious as stressed by the security agency and some sites out in the web. It tweets as follows –

It further bashes the MITREcorp and CVEnew for disregarding their disclosure guidelines, which states as follows:

Contact the affected product vendor directly

You should make a good faith effort to notify the affected vendor and work with them to ensure that a patch is available prior to publicly disclosing the vulnerability. Information is more accurate and complete when researchers and vendors work together. This practice also reduces the likelihood of a duplicate CVE ID being issued, which can happen when both a researcher and vendor request CVE IDs.

Source: cve.mitre.org

VLC even highlights a reproduction problem with the original exploit report.

We will keep you posted on this topic. You may bookmark this article for further reference. Share it within your social circle to inform your folks.

Vasan G.S.Vasan G.S.
An inquisitive mind who spends a big chunk of the day keenly tracking every emerging detail and is responsible for quickly passing on important developments to Smartprix followers. He loves to stay in his bubble scripting his destiny involving amazing technology and people with good character, passion, and brilliance.

Related Articles

ImageOnePlus Nord CE 4 Vs Nothing Phone 2a: Which one gives a better value for your money?

Recently, OnePlus launched the next in its CE series. OnePlus Nord CE 4 has been announced in India which promises premium specs at a price of under 30k. Competing with it directly is the last month launched Nothing Phone 2a which also costs under 30,000 but comes with various out-of-the-box features. While the OnePlus Nord …

ImageIndian government lifts download ban from VLC Media Player

Recently, VLC media player has been banned in India for a considerable period by the Ministry of Electronics and IT. In a recent development, the ban on VLC media player has been lifted up. The ban on the platform was imposed in February 2022, but still, information regarding the same has yet to be shared …

ImageHow to watch Dolby Vision content yon PC or Laptop?

Dolby Vision is considered as the latest and greatest HDR video format that is available as of 2022. You often see Dolby Vision pop up on the top right corner of you TV screen when you play Dolby Vision content on your TV. But did you know you can also play Dolby Vision content on …

ImageAntivirus Firm Accuses Xiaomi MIUI with Various Security Flaws

An Indian Anti-virus firm, eScan, has slammed Xiaomi’s MIUI for its severe security vulnerabilities and flaws. The firm released a report which says that MIUI poses a significant threat for apps and user data on phones. While Xiaomi has denied these accusations, eScan in its report have severely criticized various MIUI features like their uninstall …

ImageHow To Record PC Screen With VLC Media Player

VLC Media Player is one of the most versatile audio & video playback software available out there on the web. Its biggest advantage is that it is open source, supports almost all formats and it is completely free. It has various hidden features which many basic users might not be aware of. One such hidden …

Discuss

Be the first to leave a comment.