Security

IE users beware: RealPlayer zero-day flaw under attack

security-lock Hackers are actively exploiting a zero-day hole in RealNetworks’ RealPlayer media player

The in-the-wild attacks, which began late last night (October 18), targets a previously unknown and unpatched ActiveX vulnerability in the way RealPlayer interacts with Microsoft’s Internet Explorer browser.

Only systems on which both RealPlayer and IE have been installed are vulnerable.

The flaw is causing drive-by malware downloads when an IE user simply browsers to a maliciously rigged Web page, according to an alert issued by Symantec DeepSight Threat Management System.

The issue affects an ActiveX object installed by RealPlayer, accessible over the web using Internet Explorer. By instantiating the object and invoking a specific method and attacker is able to corrupt process memory and execute arbitrary code with the privileges of the browser. The attack currently known to be in-the-wild has been confirmed to download malicious code to the compromised host.


Symantec ranked the attack as a “10″ on its urgency scale because it has confirmed that attacks are being conducted in the wild; those attacks have resulted in malicious code downloaded to victimized PCs. The only bright spot: “We are not currently aware of widespread exploitation of this issue,” the company’s warning read. In another section of the advisory, it listed just two IP addresses that it has found hosting exploits of the RealPlayer bug.

Multiple versions of RealPlayer install the ActiveX control, including the current 10.5 and the beta of Version 11. RealNetworks has not released a fix, but Symantec said it had informed the media player’s maker of the bug.

“Attacks that exploit this issue may get delivered to a victim through various means, most typically, though, this style of attack is carried out through malicious Web content,” said Symantec. “For example, the exploit could be embedded in the HTML of advertisements that are published on trusted Web sites, or could be embedded as an IFrame in a compromised Web domain.”

“Real is aware of this potential vulnerability and is working on a fix,” RealNetworks’ spokesman Ryan Luckin said Friday in an e-mail. Luckin, however, declined to say when the patch would be available or whether the company would issue a security advisory of its own in the meantime.

View: Full Story

1 Comment so far »

  1. Ghillie Suits » IE users beware: RealPlayer zero-day flaw under attack said

    am October 19 2007 @ 10:43 pm

    […] Check it out! While looking through the blogosphere we stumbled on an interesting post today.Here’s a quick excerptHackers are actively exploiting a zero-day hole in RealNetworks’ RealPlayer media player The in-the-wild attacks, which began late last night (October 18), targets a previously unknown and unpatched ActiveX vulnerability in the way RealPlayer interacts with Microsoft’s Internet Explorer browser. Only systems on which both RealPlayer and IE have been installed are vulnerable. The flaw is causing drive-by malware downloads when an IE user simply browsers to a maliciously rigged Web […]

Comment RSS · TrackBack URI

Leave a comment

Name:

eMail:

Website:

Comment: