CVE-2022-32270
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).
- Affected products
- Realplayer
- Realnetworks Realplayer
- = 20.0.7.309, 20.0.8.310
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 4.4% (90th percentile)
- Weakness
- CWE-22
- NVD status
- Modified
- Published
- 2022-06-03
CVE-2022-32270 at NVD
No indexed exploits for CVE-2022-32270 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-32270 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.