Version 3.0.12 of the popular cross-platform VLC Media Player includes multiple security fixes, including patches for vulnerabilities that would allow a crash of VLC, or even execution of arbitrary code with the same system privileges as the active user.
Remote code execution (RCE) vulnerabilities can lead to anything from sensitive data being stolen, to running or installing malware, or even a full system takeover by the attacker. These vulnerabilities existed in VLC for as many as 3.5 billion installations across Linux, Mac, and Windows systems.
Specially crafted media files can be used to trick victims into opening the file with a vulnerable version of VLC Media Player. These files may look legitimate, and even play properly in VLC, while running malicious processes in the background.
Acronis Cyber Protect keeps your software up to date with the incorporated vulnerability assessment and patch management.
#VLC #vulnerability #patch #Acronis #CyberFit #CyberProtection #AcronisCyberProtectCloud #CyberSecurityNews #CPOCNews #CPOC #CyberSecurity #CyberProtect
_____
Don't get caught unaware. Stay up-to-date on what's happening in the cyber protection world. Subscribe for more news from our Cyber Protection Operation's Center.
Learn more about #CyberProtection: http://bit.ly/3iyksWL
Acronis CyberFit Summit 2022 - An MSP and IT Leaders Conference - https://bit.ly/3rJJ6JP