CVE-2007-6166

EXPLOITED

Apple QuickTime <7.3.1 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2007-6166 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 10 public exploits from researchers including Metasploit, jacky, krafty, including a Metasploit module exploits/windows/misc/apple_quicktime_rtsp_response.

AI-analyzed exploit summary This is a Metasploit module exploiting a buffer overflow in QuickTime's RTSP Content-Type header handling (CVE-2007-6166). It targets multiple Mac OS X and QuickTime versions, using architecture-specific return addresses and heap manipulation techniques to achieve remote code execution.

Description

Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac OS X, allows remote Real Time Streaming Protocol (RTSP) servers to execute arbitrary code via an RTSP response with a long Content-Type header.

Exploits (10)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteosx
https://www.exploit-db.com/exploits/16873

This is a Metasploit module exploiting a buffer overflow in QuickTime's RTSP Content-Type header handling (CVE-2007-6166). It targets multiple Mac OS X and QuickTime versions, using architecture-specific return addresses and heap manipulation techniques to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime (7.0.0, 7.1.3, 7.2.1) on Mac OS X (10.4.0, 10.4.8, 10.5.0)
No auth needed
Prerequisites: Network access to target's RTSP service · Target must process malicious RTSP response
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16424

This Metasploit module exploits a stack buffer overflow in Apple QuickTime 7.3 via an overly long RTSP response header. It sends a crafted RTSP response to trigger arbitrary code execution on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime 7.3, QuickTime Player 7.3
No auth needed
Prerequisites: Network access to the target · Target must initiate an RTSP connection to the attacker's server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by jacky · perlremotewindows
https://www.exploit-db.com/exploits/11027

This Perl script exploits a buffer overflow vulnerability in Apple QuickTime 7.2/7.3 via a malformed RTSP response. It crafts a payload with a NOP sled, shellcode, and SEH bypass to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime 7.2/7.3
No auth needed
Prerequisites: Network access to target · Target running vulnerable QuickTime version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by krafty · perlremoteosx
https://www.exploit-db.com/exploits/6013

This exploit targets a buffer overflow vulnerability in Safari + QuickTime <= 7.3 via a maliciously crafted RTSP Content-Type header. It uses heap spraying and shellcode execution to bind a shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Safari + QuickTime <= 7.3 on Mac OS X (Intel)
No auth needed
Prerequisites: Victim must browse to attacker-controlled server · QuickTime <= 7.3 must be installed
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by YAG KOHHA · textremotewindows
https://www.exploit-db.com/exploits/4664

This exploit targets a stack-based buffer overflow in QuickTime's RTSP response handling via a crafted playlist file and heap spray. It achieves remote code execution on Windows systems running IE 6/7 and QuickTime 7.2/7.3.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime 7.2/7.3, Internet Explorer 6.0/7.0
No auth needed
Prerequisites: Linux server with Perl and Apache · Remote web server to host exploit files · Target must visit malicious webpage
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by muts · pythonremotewindows
https://www.exploit-db.com/exploits/4657

This exploit targets a buffer overflow vulnerability in Apple QuickTime Player via a maliciously crafted RTSP response. It includes shellcode for a bind shell on port 4444 and is designed to work across multiple versions of QuickTime and browsers.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime Player 7.3 / 7.2
No auth needed
Prerequisites: Network access to target · QuickTime as default media player in browser
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by InTeL · c++remotewindows
https://www.exploit-db.com/exploits/4651

This exploit targets a buffer overflow vulnerability in Apple QuickTime (CVE-2007-6166) via a malformed RTSP response, leading to SEH overwrite and remote code execution on Windows Vista and XP SP2. It includes shellcode and bypasses SafeSEH by leveraging non-ASLR modules like QuickTimeStreaming.gtx.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime 7.2 and 7.3 on Windows Vista and XP SP2
No auth needed
Prerequisites: Network access to target · Target must initiate RTSP connection to attacker-controlled server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by h07 · pythondosmultiple
https://www.exploit-db.com/exploits/4648

This exploit targets a buffer overflow vulnerability in Apple QuickTime 7.3 via a malformed RTSP response. It overwrites the SEH (Structured Exception Handler) to trigger an access violation, demonstrating the potential for remote code execution.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime Player 7.3
No auth needed
Prerequisites: Network access to the target · Target must initiate an RTSP connection to the attacker's server
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/apple_quicktime_rtsp_response.rb

This Metasploit module exploits a stack buffer overflow in Apple QuickTime 7.3 via an overly long RTSP response header, allowing arbitrary code execution. The exploit crafts a malicious RTSP response with a long 'Content-Type' header to trigger the overflow and includes a payload for remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime 7.3, QuickTime Player 7.3
No auth needed
Prerequisites: Network access to the target · Target must initiate an RTSP connection to the attacker's server
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/rtsp/quicktime_rtsp_content_type.rb

This Metasploit module exploits a stack-based buffer overflow in Apple QuickTime before version 7.3.1 via an overly long RTSP response. It includes multiple targets for different macOS and QuickTime versions, leveraging return-oriented programming (ROP) techniques for code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Apple QuickTime before 7.3.1
No auth needed
Prerequisites: Network access to the target · Target must initiate an RTSP connection to the attacker's server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26549
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/3410
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/4648
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/Security-announce/2007/Dec/msg00000.html
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200803-08.xml
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/26560
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA07-334A.html
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/659761
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/38604
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6013
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3984
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27755
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29182
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018989

Scores

EPSS 0.8425
EPSS Percentile 99.3%

Details

VulnCheck KEV 2010-05-01
CWE
CWE-119
Status published
Products (26)
apple/quicktime
apple/quicktime 3.0
apple/quicktime 4.1.2
apple/quicktime 5.0
apple/quicktime 5.0.1
apple/quicktime 5.0.2
apple/quicktime 6.0
apple/quicktime 6.1
apple/quicktime 6.5
apple/quicktime 6.5.1
... and 16 more
Published Nov 29, 2007
Tracked Since Feb 18, 2026