Junglewise Threat Intelligence

CVE-2026-36911: Aleksoid1978 MPC-BE division by zero in CStreamSwitcherOutputPin

CVE-2026-36911 · Severity: info · CVSS 0 · Published 2026-07-01

Technologies: Aleksoid1978 MPC-BE. Vendors: Aleksoid1978.

Executive brief

Aleksoid1978 MPC-BE is a popular open-source media player for Windows. A vulnerability in how the player handles specific video stream data allows an attacker to crash the application by providing a specially crafted MP4 file. This could lead to a denial-of-service, preventing users from playing media or causing the application to become unresponsive.

Technical details

A division-by-zero vulnerability exists in the CStreamSwitcherOutputPin::DecideBufferSize function of MPC-BE. The flaw is triggered when the application processes a malformed MP4 file that contains unexpected values in the stream metadata, leading to an unhandled arithmetic exception. An attacker can exploit this by tricking a user into opening a crafted MP4 file, resulting in an immediate application crash (Denial of Service). The issue was addressed in commit 4341cb3.

Affected products

  • Aleksoid1978 MPC-BE (Media Player Classic Black Edition) before commit 4341cb3

Timeline

  • 2026-07-01: advisory: CVE-2026-36911 published
  • 2026-07-01: disclosed

References

Related threats