CVE-2018-4022: Mkvtoolnix Mkvinfo
High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.
A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.
Affected products
- Mkvtoolnix Mkvinfo: version 25.0.0 only
Published 2018-10-26. Last modified 2026-06-17.