Successfully exploiting this vulnerability can allow remote attackers to execute arbitrary code in the context of the application. Failed attempts will likely result in denial-of-service conditions.
QQPlayer is vulnerable to a heap-based buffer overflow, caused by improper bounds checking by the quartz.dll. By persuading a vicitm to open a specially-crafted .m2p file containing an overly long string, a remote attacker could overflow a buffer and execute arbitrary code on the system or cause the application to crash.