9.8
CVSSv3

CVE-2022-32270

Published: 03/06/2022 Updated: 12/06/2022
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

realnetworks realplayer 20.0.8.310

realnetworks realplayer 20.0.7.309