Category: IT|May 29, 2017 | Author: Admin

Subtitles can hack your machine

Share on

Update your media players now!

Update your media players now!

Security scientists at Check Point Software Technologies have discovered a whole new vulnerability in the way media players handle subtitle files, which can give an attacker full control over your computer.

Malicious subtitles bounce the machine
Custom subtitle files are treated as privileged processes by several major well-known media players, and hackers can exploit this vulnerability.

The attack occurs shortly after loading a malicious subtitle file, thus giving the attacker full control of the victim's machine.

Ready for antivirus
- Unlike other attack vectors like security companies and users familiar with, subtitles for movies are treated as harmless text files, Check Point writes on their webpages. - This means that users, antivirus and other security solutions will let them go without assessing whether they are dangerous or not, causing millions of users to be at risk.

The media players that Check Point has tested the vulnerability of include VLC, Kodi, Popcorn-time and Strem.io - all of which have come with updates for vulnerability.

Together, these media players have over 200 million users, all of whom are exposed to risk from malicious subtitles until users update their player.

These players are up to date:
- PopcornTime has created a fixed version but has not released it on the official website yet. The fix version can be downloaded manually here.
- Kodi has created a fixed version v17.2 available for download on their website. You can download the new version here.
- VLC has made an official fix version available for download on their website. It can also be downloaded here.
- Stremio has created a fixed version available for download from their website at strem.io.

Here you can see a video of how the attack occurs:

Sponsored Ads:

Comments:


Struggling with VPN

Category: Microsoft|May 3, 2024 | Author: Admin

This is how Huawei tricked its way into the US

Category: IT|May 2, 2024 | Author: Admin

Edge 125 arrives in Beta with sleeping tab improvements and other changes

Category: IT|May 1, 2024 | Author: Admin

Now the iPad opens

Category: Apple|Apr 30, 2024 | Author: Admin

Woke up locked out of Apple ID on iPhone

Category: Apple|Apr 29, 2024 | Author: Admin

Google has a hidden collection of highly-addictive retro games

Category: Google|Apr 28, 2024 | Author: Admin

Google is officially a $2 trillion company

Category: Google|Apr 27, 2024 | Author: Admin

Snowden: “DO NOT use Reddit!”

Category: IT|Apr 26, 2024 | Author: Admin

Popular Google app used by millions set to close in a few weeks

Category: Google|Apr 25, 2024 | Author: Admin

Cheeky, YouTube!

Category: Google|Apr 24, 2024 | Author: Admin

This is the date Apple will reveal new iPads

Category: Apple|Apr 23, 2024 | Author: Admin

Only possible with VPN

Category: IT|Apr 22, 2024 | Author: Admin

Apple sidles into sideloading in the EU

Category: Apple|Apr 21, 2024 | Author: Admin

Report: Microsoft-OpenAI ownership might get conditional OK from EU regulators

Category: IT|Apr 20, 2024 | Author: Admin

Giant change at Google could change everything

Category: Google|Apr 19, 2024 | Author: Admin
more