Attackers feast on Real Player flaw

Real promises to patch hole as soon as possible

Written by Shaun Nichols in California

Online criminals are exploiting a new, unpatched vulnerability in the Real Player application.

Security firm Symantec said that fewer than 50 infections had been reported, and that the attack is currently limited to just a few websites.

The attack targets an unpatched vulnerability in the RealPlayer media player application.

Real Networks told vnunet.com that a fix for the vulnerability should be up by the end of Friday (19 October).

The vulnerability lies in the way a Real Player component handles ActiveX calls. ActiveX is a system used to link Internet Explorer with other applications such as Real's media player.

When the user accesses a specially crafted web page, malicious javascript is run which targets the vulnerability and installs a trojan.

This trojan in turn downloads and installs another piece of malware which lowers the security settings in Internet Explorer, making it easier to carry out future attacks on the user's system.

Upon successfully executing the exploit, RealPlayer then plays a standard test video.

Symantec said that Firefox is not believed to be affected by the flaw, as it does not utilize ActiveX.

The company notes that this is not the first time a flaw in the component, known as ierpplug.dll, has been reported. Last December, a security researcher was able to exploit the component to achieve a denial of service.

The US Computer Emergency Response Team (US-CERT) advises users to disable ActiveX controls until a fix becomes available.

Symantec noted that advanced users can also mitigate the risk by setting a kill bit in the Windows registry, which will prevent the vulnerable ActiveX control from running.

See also:

reader comments

related articles

 

Security experts warn of IE6 flaw

New attack for an old browser 27 Jun 2008

Attackers gun for Adobe flaw

Worms still targeting Reader vulnerabilities 12 Nov 2008

Attackers gun for new ActiveX flaws

Facebook, MySpace and Yahoo all targeted 06 Feb 2008

latest news

Ironport slams partner margin erosion claim

UK partner manager hails content security vendor’s acquisition by Cisco as a boon for UK resellers 09 Jan 2009

Sun sets higher bar with telemarketing budget

Vendor plans to turn its popularity among the open-source community into a revenue stream 09 Jan 2009

Marathon signs up 14 resellers and counting

Vendor is sprinting full steam ahead in a race to widen its channel reach 09 Jan 2009

poll

Challenging times ahead?

Challenging times ahead?

Do you think there will be a lot of channel job cuts in 2009?

Previous poll results

Paul Anderson, Trend Micro

Vendor Q&A: Paul Anderson, Trend Micro

During this Q&A session Paul Anderson, UK country manager of Trend Micro talks about the changing threat landscape and how Trend is working with resellers in 2009

Sara Yirrell and Rick Wallis

Vendor Q&A: Rick Wallis, NEC Computers

In this exclusive vendor Q&A, Rick Wallis, UK sales director at NEC Computers talks to CRN editor Sara Yirrell about his firm’s plans for the channel.

events

Channel Expo 2009 logo

Channel Expo 2009

The UK's top reseller exhibition will return to the NEC on 20 May 2009

CRN Fight Night 2009

The channel's only white-collar boxing event is back

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

White papers

Search white papers

Top categories

Primary Navigation