RealPlayer versions up to 11.0.1 (build 22.214.171.1244) have a vulnerability in the rmoc3260.dll ActiveX control which can lead to remote code execution.The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll 126.96.36.199 in RealNetworks RealPlayer 11.0.1 build 188.8.131.524 does not properly manage memory for the Console property, which allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via a series of assignments of long string values, which triggers an overwrite of freed heap memory. NOTE: some of these details are obtained from third party information.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center