topbanner_forum
  *

avatar image

Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
  • Friday April 19, 2024, 4:24 pm
  • Proudly celebrating 15+ years online.
  • Donate now to become a lifetime supporting member of the site and get a non-expiring license key for all of our programs.
  • donate

Author Topic: Attacks exploiting RealPlayer zero-day security risk  (Read 7637 times)

mouser

  • First Author
  • Administrator
  • Joined in 2005
  • *****
  • Posts: 40,900
    • View Profile
    • Mouser's Software Zone on DonationCoder.com
    • Read more about this member.
    • Donate to Member
Attacks exploiting RealPlayer zero-day security risk
« on: October 20, 2007, 02:24 PM »
This one sounds a bit serious..

October 19, 2007 (Computerworld) -- Attackers are exploiting a zero-day vulnerability in RealPlayer in order to infect Windows machines running Internet Explorer, Symantec Corp. said late Thursday. The security company issued an alert that rated the threat with its highest possible score.

According to a warning issued to customers of its DeepSight threat network, Symantec said an ActiveX control installed by RealNetworks Inc.'s RealPlayer program is flawed. When combined with Microsoft Corp.'s Internet Explorer (IE) browser -- which relies on ActiveX controls to extend its functionality -- the bug can be exploited and malicious code downloaded to any PC that wanders to a specially crafted site.

Only systems on which both RealPlayer and IE have been installed are vulnerable.

Symantec ranked the attack as a "10" on its urgency scale because it has confirmed that attacks are being conducted in the wild; those attacks have resulted in malicious code downloaded to victimized PCs.

« Last Edit: October 20, 2007, 02:26 PM by mouser »

mouser

  • First Author
  • Administrator
  • Joined in 2005
  • *****
  • Posts: 40,900
    • View Profile
    • Mouser's Software Zone on DonationCoder.com
    • Read more about this member.
    • Donate to Member
Re: Attacks exploiting RealPlayer zero-day security risk
« Reply #1 on: October 20, 2007, 02:26 PM »
Anyone know a utility for disabling activex plugins? Does nirsoft have one?

Lashiec

  • Member
  • Joined in 2006
  • **
  • Posts: 2,374
    • View Profile
    • Donate to Member
Re: Attacks exploiting RealPlayer zero-day security risk
« Reply #2 on: October 20, 2007, 02:54 PM »
Yes, it does. But you can deactivate ActiveX in IE7 as well, under Tools -> Addons Management (made up translation).

This is the price to pay for using RealPlayer >:D

nudone

  • Cody's Creator
  • Columnist
  • Joined in 2005
  • ***
  • Posts: 4,119
    • View Profile
    • Donate to Member
Re: Attacks exploiting RealPlayer zero-day security risk
« Reply #3 on: October 20, 2007, 02:57 PM »
dumb question, but would this also include 'real alternative' codec as i assume a lot of the real player content has been stripped away?

(can't get the referenced article to load at the moment.)

mouser

  • First Author
  • Administrator
  • Joined in 2005
  • *****
  • Posts: 40,900
    • View Profile
    • Mouser's Software Zone on DonationCoder.com
    • Read more about this member.
    • Donate to Member
Re: Attacks exploiting RealPlayer zero-day security risk
« Reply #4 on: October 20, 2007, 03:10 PM »
Thanks Lashiec, found realplayer activex in that list and disabled it.

nudone

  • Cody's Creator
  • Columnist
  • Joined in 2005
  • ***
  • Posts: 4,119
    • View Profile
    • Donate to Member
Re: Attacks exploiting RealPlayer zero-day security risk
« Reply #5 on: October 21, 2007, 03:24 AM »
there is now an official fix for the exploit:

http://service.real....ty/191007_player/en/