Remote exploitation of a memory corruption vulnerability in RealNetworks Inc.'s RealPlayer media player could allow attackers to execute arbitrary code in the context of the targeted user.
The vulnerability specifically exists in the way RealPlayer handles specially crafted RealMedia files using AAC codec. When decoding an AAC audio stream in a specially crafted RealMedia file, RealPlayer uses a value from the file without properly validating it, which leads to heap memory corruption and an exploitable condition.
Vendor Status:
RealNetworks has released patches and workarounds to address this vulnerability.