In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.
References
Link | Resource |
---|---|
https://github.com/Edubr2020/RP_RecordClip_DLL_Hijack | Third Party Advisory |
Configurations
Information
Published : 2022-06-05 15:15
Updated : 2022-06-14 07:07
NVD link : CVE-2022-32291
Mitre link : CVE-2022-32291
JSON object : View
CWE
Products Affected
realnetworks
- realplayer