Popular video and media player VideoLan Client (VLC) has been found by security researchers to have two serious vulnerabilities, allowing malicious .avi and .mkv files to execute any code with full user privileges. Version 3.0.7 or newer addresses this vulnerability, so check to make sure your version is up-to-date.
https://www.notebookcheck.net/PSA-Update-your-copy-of-VLC-to-avoid-allowing-hackers-full-control-of-your-computer-when-opening-video-files.425384.0.html