Loading
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
Use CWE-427, Videolan vendor hub and Vlc Media Player product page to widen CVE-2023-46814 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-47359, CVE-2022-41325 and CVE-2020-26664 for nearby disclosures in the same product family.