Short Name |
APP:REAL:QCPFFORMAT-DLL-RCE |
|---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
APP |
Keywords |
RealPlayer Real Networks Metasploit Core IMPACT QCP |
Release Date |
2011/09/27 |
Update Number |
2000 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known flaw in Real Networks RealPlayer. Versions 14.0.6 and below are affected. A successful attack results in arbitrary code execution with the privileges of the targeted user, possibly an administrator. Both Core IMPACT and Metasploit Framework have exploit modules for this vulnerability.
Real Networks RealPlayer is prone to a remote code-execution vulnerability. Successful exploits will allow remote attackers to execute arbitrary code within the context of the affected application. Failed attacks may cause denial-of-service conditions. Versions prior to RealPlayer for Windows 14.0.6 are vulnerable. NOTE: This issue was previously discussed in BID 49169 (Real Networks RealPlayer Multiple Remote Vulnerabilities) but has been given its own record to better document it.