CVE-2011-0531
VLC media player < 1.1.6.1 - Remote Code Execution via Crafted MKV File
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2011-0531.
PoCs published by Metasploit, Dan Rosenberg, including Metasploit module exploits/windows/fileformat/vlc_webm.
AI-analyzed exploit summary This exploit leverages a memory corruption vulnerability in VLC media player by crafting a malicious MKV/WebM file. It uses heap spraying and ROP techniques to achieve arbitrary code execution on Windows XP SP3.
Description
demux/mkv/mkv.hpp in the MKV demuxer plugin in VideoLAN VLC media player 1.1.6.1 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary commands via a crafted MKV (WebM or Matroska) file that triggers memory corruption, related to "class mismatching" and the MKV_IS_ID macro.
Exploits (2)
This exploit leverages a memory corruption vulnerability in VLC media player by crafting a malicious MKV/WebM file. It uses heap spraying and ROP techniques to achieve arbitrary code execution on Windows XP SP3.
This Metasploit module exploits a memory corruption vulnerability in VideoLAN VLC < 1.1.7 by crafting a malicious WebM file. It leverages heap spraying and ROP techniques to achieve arbitrary code execution on Windows XP SP3.