EIP-2026-116162

PRE-CVE

RealMedia RealPlayer 10.5/11 - 'ierpplug.dll' PlayerProperty ActiveX Control Buffer Overflow

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-116162. PoCs published by Elazar Broad.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the RealPlayer ActiveX control by supplying an excessively long string to the 'PlayerProperty' method, potentially leading to arbitrary code execution. The PoC uses JavaScript to trigger the vulnerability when the page loads.

Description

RealMedia RealPlayer 10.5/11 - 'ierpplug.dll' PlayerProperty ActiveX Control Buffer Overflow

Exploits (1)

exploitdb WORKING POC VERIFIED
by Elazar Broad · htmldoswindows
https://www.exploit-db.com/exploits/30812

This exploit targets a buffer overflow vulnerability in the RealPlayer ActiveX control by supplying an excessively long string to the 'PlayerProperty' method, potentially leading to arbitrary code execution. The PoC uses JavaScript to trigger the vulnerability when the page loads.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: RealPlayer 10.5
No auth needed
Prerequisites: Victim must open the malicious HTML file in a browser with the vulnerable ActiveX control enabled
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026