RealPlayer exploit discovered


Previously unknown RealPlayer exploitation was discovered last week. So far, it can be told that unpatched vulnerability affects the latest versions of RealPlayer and RealPlayer 11 BETA, although older versions may also be vulnerable. Furthermore, an ActiveX object in the RealPlayer component ierpplug.dll is affected. This is not the first case of exploitation of this DLL, although only remote denial of service was achieved on previous occasions.

The several versions of RealPlayer are checked when you enter a malicious website to determine whether the application is vulnerable, if positive, Trojan.Reapall exploits the vulnerability, downloading and executing a copy of Trojan.Zonebac. This means that it’s enough just to visit a malicious website, the player does not need to be running.

To avoid this you have to set the kill bit on the Class identifier (CLSID) FDC7A535-4070-4B92-A0EA-D9994BCC0DC5, (instructions can be found here). Also ensure that your Internet Explorer clients are configured to prompt before executing Active Scripting, which should be disabled altogether, if not required. Update your antivirus software and disable your JavaScript whenever possible.







3 Responses to “RealPlayer exploit discovered”

  1. Daniel Obertan Says:
    June 19th, 2011 at 11:24 am

    Already bookmarked your site.. :)

  2. Daniel Obertan Says:
    June 19th, 2011 at 11:42 am

    Great words for this great title.. :)

  3. Daniel Obertan Says:
    June 19th, 2011 at 11:42 am

    Great article.. Enjoying your word by word..

Your opinion regarding RealPlayer exploit discovered

Spreading the knowledge:

It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
add text box
rss feed
help other
News

Subscribe to spyware news

Please enter your e-mail address:
If you do not want to receive our spyware
newsletter, please unsubscribe here.
Articles