CVE-2002-1643

RealNetworks Helix Universal Server 9.0.2.768 - Remote Code Execution via RTSP/HTTP Request Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2002-1643. PoCs published by Metasploit, Johnny Cyberpunk, H D Moore, including Metasploit module exploits/multi/realserver/describe.

AI-analyzed exploit summary This Metasploit module exploits a buffer overflow in RealServer via a malformed RTSP DESCRIBE request. It targets multiple platforms (Linux, BSD, Windows) and includes a payload delivery mechanism.

Description

Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbitrary code via (1) a long Transport field in a SETUP RTSP request, (2) a DESCRIBE RTSP request with a long URL argument, or (3) two simultaneous HTTP GET requests with long arguments.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/16286

This Metasploit module exploits a buffer overflow in RealServer via a malformed RTSP DESCRIBE request. It targets multiple platforms (Linux, BSD, Windows) and includes a payload delivery mechanism.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RealServer 7/8/9
No auth needed
Prerequisites: Network access to the RTSP service · Vulnerable RealServer version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Johnny Cyberpunk · cremotewindows
https://www.exploit-db.com/exploits/23

This exploit targets a buffer overflow vulnerability in RealServer versions prior to 8.0.2 via a crafted RTSP SETUP request. It delivers a reverse shell payload to spawn a command shell on TCP port 31337.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RealServer < 8.0.2
No auth needed
Prerequisites: Network access to TCP port 554 (RTSP) on the target · Target running vulnerable RealServer version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by H D Moore · rubyremotemultiple
https://www.exploit-db.com/exploits/9937

This exploit targets a buffer overflow in RealServer 7/8/9 via a malformed RTSP DESCRIBE request. It uses a universal payload to achieve remote code execution on Linux, BSD, and Windows systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RealServer 7/8/9
No auth needed
Prerequisites: Network access to the RTSP service · Vulnerable RealServer version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC GREAT
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/realserver/describe.rb

This Metasploit module exploits a buffer overflow in RealServer 7/8/9 via a malformed RTSP DESCRIBE request. It targets multiple platforms (Linux, BSD, Windows) and delivers a payload encoded in hex to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: RealServer 7/8/9
No auth needed
Prerequisites: Network access to the RTSP service · Vulnerable RealServer version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10916
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/974689
Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/304203
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10915
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6454
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6456
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6458
Vendor Advisory x_refsource_misc
http://www.nextgenss.com/advisories/realhelix.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10917

Scores

EPSS 0.7432
EPSS Percentile 99.4%

Details

Status published
Products (2)
realnetworks/helix_universal_server 9.0
realnetworks/helix_universal_server 9.0.2.768
Published Dec 19, 2002
Tracked Since Feb 18, 2026