Attackers feast on Real Player flaw

Real promises to patch hole as soon as possible

Written by Shaun Nichols in California

Online criminals are exploiting a new, unpatched vulnerability in the Real Player application.

Security firm Symantec said that fewer than 50 infections had been reported, and that the attack is currently limited to just a few websites.

The attack targets an unpatched vulnerability in the RealPlayer media player application.

Real Networks told vnunet.com that a fix for the vulnerability should be up by the end of Friday (19 October).

The vulnerability lies in the way a Real Player component handles ActiveX calls. ActiveX is a system used to link Internet Explorer with other applications such as Real's media player.

When the user accesses a specially crafted web page, malicious javascript is run which targets the vulnerability and installs a trojan.

This trojan in turn downloads and installs another piece of malware which lowers the security settings in Internet Explorer, making it easier to carry out future attacks on the user's system.

Upon successfully executing the exploit, RealPlayer then plays a standard test video.

Symantec said that Firefox is not believed to be affected by the flaw, as it does not utilize ActiveX.

The company notes that this is not the first time a flaw in the component, known as ierpplug.dll, has been reported. Last December, a security researcher was able to exploit the component to achieve a denial of service.

The US Computer Emergency Response Team (US-CERT) advises users to disable ActiveX controls until a fix becomes available.

Symantec noted that advanced users can also mitigate the risk by setting a kill bit in the Windows registry, which will prevent the vulnerable ActiveX control from running.

Tags:

reader comments

related articles

 

Security experts warn of IE6 flaw

New attack for an old browser 27 Jun 2008

Apple QuickTime exploit goes wild

Streaming media flaw used to push malware 04 Dec 2007

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users 27 Nov 2007

related whitepapers

today's top stories

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

City in pressing need of skilled IT matchmakers

With the financial services sector plunging ever deeper into an M&A maelstrom, IT leaders are having their systems integration skills and due diligence expertise tested as never before 09 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you apply for a job that was advertised on Facebook or a similar social networking site?

Would you apply for a job that was advertised on Facebook or a similar social networking site?

The government is using Facebook to recruit IT staff - would you apply to such an ad?

Previous poll results

Latest audio and video articles

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Podcast imageAudio

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation