CVE-2026-56711
VLC media player 3.0.0 through 3.0.23 memory corruption vulnerability
Description
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
In plain language
AI Act nowVLC media player 3.0.0 through 3.0.23 can be crashed or taken over if someone opens a malicious media file, so small businesses should treat unexpected media files as unsafe until a fix is available.
A high-severity local memory-corruption flaw (CWE-190/CWE-787) in VLC’s processing of crafted media files may cause application termination or code execution in the VLC process context.
What to do now
- Check whether VLC media player is installed and identify its version.
- If it is 3.0.0 through 3.0.23, tell staff not to open unexpected media files with VLC.
- No fixed version has been published; ask your software vendor or IT provider to track and deploy the vendor’s update when available.
- Remove or isolate suspicious media attachments and downloads before users open them.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-56711 and every CVE in our database. Create a free account — no credit card required.
Create Free Account