CyberRota Analysis
AI-GeneratedVLC media player versions prior to 3.0.24 are susceptible to a path traversal vulnerability in the skins2 ThemeLoader, allowing attackers to exploit improperly validated member names in .vlt skin archives. This flaw enables the creation of malicious skin files that can write arbitrary files with the same privileges as the VLC user, potentially leading to code execution via Lua script injection. Organizations using VLC media player should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.