GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction.
| Software | From | Fixed in |
|---|---|---|
| gomlab / gom_player | 2.3.90.5360 | 2.3.90.5360.x |