Severity: High
22 October, 2007
Summary:
Late Friday, RealNetworks released a patch for a critical vulnerability affecting RealPlayer 10.5 and RealPlayer 11 beta running on Windows. By enticing one of your users to a malicious Web site, an attacker can exploit this vulnerability to execute code on your user¡¯s computer, with your user¡¯s privileges. In the worst case scenario, the attacker could gain total control of the victim¡¯s PC. If you allow the use of RealPlayer in your network, have your users upgrade immediately.
Exposure:
RealPlayer and RealOne Player are widely-used software for Internet media delivery. RealOne Player plays virtually every major Internet media format, including Windows Media, Quicktime, MPEG-4, and even DVDs. If you¡¯ve watched streaming videos on the Internet, or listened to music samples while buying CDs online, you¡¯ve probably encountered RealPlayer.
WatchGuard does not recommend using RealPlayer or RealOne Player, partly because both contain automatic communication features which, by default, let RealNetworks and RealNetwork¡¯s ¡°partners¡± (such as NASCAR and CNN) install software on your client computers. But in reality, many of your users have probably installed one of these products, with or without your
¡¦