Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Attacks exploiting RealPlayer zero-day in progress

Buggy ActiveX control also implicates Internet Explorer, says Symantec

October 19, 2007 12:00 PM ET

Computerworld - Attackers are exploiting a zero-day vulnerability in RealPlayer in order to infect Windows machines running Internet Explorer, Symantec Corp. said late Thursday. The security company issued an alert that rated the threat with its highest possible score.

According to a warning issued to customers of its DeepSight threat network, Symantec said an ActiveX control installed by RealNetworks Inc.'s RealPlayer program is flawed. When combined with Microsoft Corp.'s Internet Explorer (IE) browser -- which relies on ActiveX controls to extend its functionality -- the bug can be exploited and malicious code downloaded to any PC that wanders to a specially crafted site.

Only systems on which both RealPlayer and IE have been installed are vulnerable.

Symantec ranked the attack as a "10" on its urgency scale because it has confirmed that attacks are being conducted in the wild; those attacks have resulted in malicious code downloaded to victimized PCs. The only bright spot: "We are not currently aware of widespread exploitation of this issue," the company's warning read. In another section of the advisory, it listed just two IP addresses that it has found hosting exploits of the RealPlayer bug.

Multiple versions of RealPlayer install the ActiveX control, including the current 10.5 and the beta of Version 11. RealNetworks has not released a fix, but Symantec said it had informed the media player's maker of the bug.

"Attacks that exploit this issue may get delivered to a victim through various means, most typically, though, this style of attack is carried out through malicious Web content," said Symantec. "For example, the exploit could be embedded in the HTML of advertisements that are published on trusted Web sites, or could be embedded as an IFrame in a compromised Web domain."

Symantec also referenced a blog that had posted some information about the RealPlayer vulnerability Wednesday morning. The blogger, identified only as Roger, claimed that the NASA space agency has warned workers not to use IE because of an unspecified problem with RealPlayer.

Roger quoted from what he claimed was a NASA bulletin. "The malware appears to be spreading through a large variety of common and highly-respected Internet sites," the NASA warning reportedly said. "However it does not appear these sites are themselves infected. The affected sites are serving solely as a mechanism to attract potential victims." NASA's public affairs team at the Ames Research Center in northern California was not available for comment Thursday night.

Until RealNetworks releases a patch, Symantec said the best advice it can give is to disable the vulnerable ActiveX control by setting its "kill bit." To do that, however, requires editing the Windows registry, a task most users shy away from.

More information will be posted to this page on the SecurityFocus Web site, which Symantec operates, when it is available.

"Real is aware of this potential vulnerability and is working on a fix," RealNetworks' spokesman Ryan Luckin said Friday in an e-mail. Luckin, however, declined to say when the patch would be available or whether the company would issue a security advisory of its own in the meantime.



Jump to comments

RealPlayer

Additional Resources

Xerox
By using solid ink technology only from Xerox, you could save up to 65% by printing color for the cost of black and white. Enter for a chance to WIN a PhaserTM 8860 network color printer!
Microsoft
Save time and mitigate security risk. Deploy it now.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...