Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

BS.Player Buffer Overflow Vulnerability in Playlist Import Functionality

Vulnerability

A buffer overflow vulnerability has been identified in BS.Player version 2.57 (build 1051) within the playlist import feature. The issue arises when the application processes .m3u files, as it does not properly validate the length of playlist entries. This oversight leads to a buffer overflow, allowing the manipulation of Structured Exception Handler (SEH) records. The vulnerability is triggered by opening a crafted playlist file, exploiting the Unicode parsing logic in the Windows client.

Impact

Exploitation of this vulnerability leads to a buffer overflow condition, allowing for arbitrary code execution by overwriting SEH records.

Reproduction

The vulnerability can be reproduced by importing a specially crafted .m3u playlist file into BS.Player version 2.57 (build 1051). The crafted file should contain long URLs that exceed the application's input validation, triggering the buffer overflow when the playlist is opened.

Added: Aug 30, 2025, 2:32 PM
Updated: Aug 30, 2025, 2:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
8.1
remediation
0.0
relevance
0.4
threat
9.3
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.