ALT-PU-2023-8665-1

Обновление пакета vlc в ветке sisyphus

Версия3.0.19-alt1
Задание#331529
Опубликовано2023-10-24
Макс. серьёзностьHIGH
Серьёзность:

Закрытые проблемы (1)

CVE-2023-46814
HIGH7.8

A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.

Опубликовано: 2023-11-22Изменено: 2024-11-21
CVSS 3.xВЫСОКАЯ 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H