CVE-2018-19357

HIGH

XMPlay 3.8.3 - Remote Code Execution via Crafted HTTP URL in M3U File

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-19357. PoCs published by s7acktrac3.

AI-analyzed exploit summary This exploit leverages a buffer overflow in XMPlay 3.8.3 via a maliciously crafted .m3u file to achieve remote code execution, specifically launching calc.exe. It uses an egghunter technique to locate and execute the payload in memory.

Description

XMPlay 3.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (stack-based buffer overflow) via a crafted http:// URL in a .m3u file.

Exploits (1)

exploitdb WORKING POC
by s7acktrac3 · pythonlocalwindows
https://www.exploit-db.com/exploits/46020

This exploit leverages a buffer overflow in XMPlay 3.8.3 via a maliciously crafted .m3u file to achieve remote code execution, specifically launching calc.exe. It uses an egghunter technique to locate and execute the payload in memory.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: XMPlay 3.8.3
No auth needed
Prerequisites: Victim must open the maliciously crafted .m3u file in XMPlay
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://exploit-db.com/exploits/46020/

Scores

CVSS v3 7.8
EPSS 0.0311
EPSS Percentile 86.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (1)
xmplay/xmplay 3.8.3
Published Dec 24, 2018
Tracked Since Feb 18, 2026