CVE-2018-4022: Mkvtoolnix Mkvinfo

High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.

A use-after-free vulnerability exists in the way MKVToolNix MKVINFO v25.0.0 handles the MKV (matroska) file format. A specially crafted MKV file can cause arbitrary code execution in the context of the current user.

Affected products

Published 2018-10-26. Last modified 2026-06-17.