Vulnerability record · CVE-2007-0015 · published 1 January 2007
CVE-2007-0015: Apple QuickTime buffer overflow via long rtsp:// URI
Apple · Quicktime
Apple QuickTime 7.1.3 contains a buffer overflow that is triggered when processing an overly long rtsp:// URI. A remote attacker can deliver a crafted URI to crash the application or execute arbitrary code in the context of the user running QuickTime. The flaw matters because QuickTime is widely deployed and the attack requires no authentication.
Description
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Automated analysis
high priorityPublic exploit code exists and EPSS is very high, but the CVSS base score is medium and exploitation requires user interaction, making it a high priority for patching rather than critical.
What it is
Apple QuickTime 7.1.3 contains a buffer overflow that is triggered when processing an overly long rtsp:// URI. A remote attacker can deliver a crafted URI to crash the application or execute arbitrary code in the context of the user running QuickTime. The flaw matters because QuickTime is widely deployed and the attack requires no authentication.
Impact
An attacker can execute arbitrary code with the privileges of the QuickTime user, leading to full compromise of the affected host. If the user has administrative rights, the attacker could take complete control of the system.
Attack surface
The vulnerability is reached remotely over the network by supplying a long rtsp:// URI to QuickTime, typically via a web page, email, or other application that invokes the handler. No authentication is required, but some user interaction (such as opening a link or file) is likely needed to trigger the parsing of the URI.
Exploitation
Exploit code is publicly referenced in multiple sources, and EPSS indicates a high probability of exploitation activity (0.48669, 98.8th percentile). The vulnerability is not listed in CISA KEV, but the presence of public exploits and the age of the flaw make exploitation likely in unpatched environments.
What to do
- Apply the vendor patch from Apple as referenced in the security advisory (Apple Security Announce, Secunia advisory 23540, and US-CERT alert TA07-005A).
- If patching is not immediately possible, disable or restrict the rtsp:// URI handler for QuickTime, or remove QuickTime if it is not required.
- Block or filter rtsp:// URIs at email and web gateways where feasible to reduce exposure.
- Educate users not to open untrusted links or files that may invoke QuickTime.
- Consider application whitelisting or endpoint controls to prevent QuickTime from launching from untrusted sources.
Detection
- Monitor for processes spawning QuickTime with unusual command-line arguments containing long rtsp:// strings.
- Inspect network traffic for rtsp:// URIs with abnormally long or malformed parameters.
- Review endpoint logs for crashes or exceptions in QuickTime or related components.
- Use file integrity monitoring to detect unauthorized changes to QuickTime binaries or plugins.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0015 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0015), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.