RealNetworks RealPlayer CDDA URI ActiveX Exploit

This module exploits a vulnerability in RealPlayer. The vulnerable software does not properly initialize an unspecified object component during parsing of a malformed CDDA URI. This module runs a malicious web site on the Core Impact Console and waits for an unsuspecting user to trigger the exploit by connecting to the web site. This module runs a web server waiting for vulnerable clients (Internet Explorer 6 or 7) to connect to it. When the client connects, it will try to install an agent by exploiting this vulnerability.
Exploit Platform
Exploit Type
Product Name