Skip to main content

RealPlayer ActiveX Control "Console" Memory Corruption Vulnerability

Last Update Date: 28 Jan 2011 Release Date: 12 Mar 2008 4455 Views

RISK: Medium Risk

A vulnerability has been identified in RealPlayer, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a memory corruption error in the "rmoc3260.dll" ActiveX control when handling the "Console" property, which could be exploited by remote attackers to crash an affected browser or execute arbitrary code by tricking a user into visiting a specially crafted web page.


Impact

  • Remote Code Execution

System / Technologies affected

  • RealPlayer version 11.0.1 (build 6.0.14.794) including rmoc3260.dll version 6.0.10.45

Solutions

There is no patch available for this vulnerability currently.

Temporary Solution: Set the kill-bit for the affected ActiveX control.


Vulnerability Identifier

  • No CVE information is available

Source


Related Link