Executive brief
Aleksoid1978 MPC-BE is a popular open-source media player for Windows. A vulnerability in how the player handles specific video stream data allows an attacker to crash the application by providing a specially crafted MP4 file. This could lead to a denial-of-service, preventing users from playing media or causing the application to become unresponsive.
Technical details
A division-by-zero vulnerability exists in the CStreamSwitcherOutputPin::DecideBufferSize function of MPC-BE. The flaw is triggered when the application processes a malformed MP4 file that contains unexpected values in the stream metadata, leading to an unhandled arithmetic exception. An attacker can exploit this by tricking a user into opening a crafted MP4 file, resulting in an immediate application crash (Denial of Service). The issue was addressed in commit 4341cb3.
Affected products
- Aleksoid1978 MPC-BE (Media Player Classic Black Edition) before commit 4341cb3
Timeline
- 2026-07-01: advisory: CVE-2026-36911 published
- 2026-07-01: disclosed