CVE-2022-32271

CRITICAL

Realnetworks Realplayer - XSS

Title source: rule

Description

In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.

Scores

CVSS v3 9.6
EPSS 0.0272
EPSS Percentile 85.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Classification

CWE
CWE-79
Status published

Affected Products (1)

realnetworks/realplayer

Timeline

Published Jun 03, 2022
Tracked Since Feb 18, 2026