CVE-2022-32271: XSS
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-32271?
CVE-2022-32271 has been classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2022-32271?
To fix CVE-2022-32271, update RealPlayer to a patched version released by RealNetworks.
What type of vulnerability is CVE-2022-32271?
CVE-2022-32271 is a remote arbitrary code execution vulnerability exploited through the DCP:// URI protocol.
Who is affected by CVE-2022-32271?
CVE-2022-32271 affects users of RealPlayer version 20.0.8.310.
Can CVE-2022-32271 lead to data breaches?
Yes, CVE-2022-32271 can potentially lead to unauthorized access and data breaches through code execution.