Vulnerability record · CVE-2011-0257 · published 15 August 2011
CVE-2011-0257: Apple QuickTime PICT PnSize opcode stack buffer overflow
Apple · Quicktime
Apple QuickTime before 7.7 has an integer signedness error when parsing the PnSize opcode in a PICT file, which leads to a stack-based buffer overflow. A crafted PICT file can crash the application or allow remote code execution. The flaw matters because PICT files are commonly opened through browsers, mail clients and file previews, so a single malicious image can reach the vulnerable parser.
Description
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PnSize opcode in a PICT file that triggers a stack-based buffer overflow.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe CVSS 2.0 score is 9.3 with complete confidentiality, integrity and availability impact, public exploit code exists, and EPSS is near the top percentile, though the flaw requires user interaction and affects an aging product.
What it is
Apple QuickTime before 7.7 has an integer signedness error when parsing the PnSize opcode in a PICT file, which leads to a stack-based buffer overflow. A crafted PICT file can crash the application or allow remote code execution. The flaw matters because PICT files are commonly opened through browsers, mail clients and file previews, so a single malicious image can reach the vulnerable parser.
Impact
An attacker can execute arbitrary code in the context of the user running QuickTime, or at minimum crash the application. Successful exploitation gives full control over confidentiality, integrity and availability on the affected host.
Attack surface
The vector is network-reachable with medium complexity and no authentication (AV:N/AC:M/Au:N), meaning the victim must open or preview a crafted PICT file. No credentials are required, but user interaction with the malicious file is needed.
Exploitation
CVE-2011-0257 is not listed in CISA KEV, but EPSS shows a 30-day probability of about 0.60 (99th percentile), and a public Exploit-DB entry (17777) plus a ZDI advisory exist, indicating exploit code is publicly available.
What to do
- Upgrade Apple QuickTime to version 7.7 or later, which contains the vendor fix described in Apple advisory HT4826.
- If QuickTime cannot be updated or is no longer needed, uninstall it or disable PICT handling and browser/plugin integration.
- Block or strip PICT files at email and web gateways where business use does not require them.
- Restrict execution of QuickTime and its browser plugins to trusted users and apply least-privilege accounts.
- Monitor vendor advisories for any further QuickTime fixes, since this product line has a history of parser flaws.
Detection
- Search endpoint logs and EDR telemetry for QuickTime processes (QuickTimePlayer.exe, qttask.exe) spawning child processes or writing executables after opening media files.
- Alert on PICT files (.pct, .pict) delivered via email attachments or web downloads, especially from external senders.
- Use file inspection or YARA rules to flag PICT files containing malformed PnSize opcodes and oversized size fields.
- Correlate QuickTime crash reports (stack overflow in the PICT parser) with subsequent suspicious process activity on the same host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0257 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0257), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.