Vulnerability record · CVE-2013-7260 · published 3 January 2014
CVE-2013-7260: RealPlayer RMP XML declaration stack buffer overflow
RRealnetworks · Realplayer
RealNetworks RealPlayer on Windows (before 17.0.4.61) and Mac (before 12.0.1.1738) contains multiple stack-based buffer overflows in the handling of the XML declaration of an RMP file. A long version number or encoding declaration overflows a stack buffer, which can lead to arbitrary code execution. The flaw is distinct from CVE-2013-6877.
Description
Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a high EPSS score and public exploit code, though no confirmed in-the-wild or KEV activity is recorded.
What it is
RealNetworks RealPlayer on Windows (before 17.0.4.61) and Mac (before 12.0.1.1738) contains multiple stack-based buffer overflows in the handling of the XML declaration of an RMP file. A long version number or encoding declaration overflows a stack buffer, which can lead to arbitrary code execution. The flaw is distinct from CVE-2013-6877.
Impact
An attacker can execute arbitrary code in the context of the user running RealPlayer, giving full control of the affected process and potentially the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
Reached remotely over the network with no authentication required (AV:N/AC:L/Au:N), typically by delivering a crafted RMP file that the victim opens in RealPlayer. User interaction to open or play the malicious file is implied by the file-based vector, though the record does not state it explicitly.
Exploitation
Not listed in CISA KEV, but EPSS is 0.66885 (99.259th percentile), indicating a high modeled likelihood of exploitation, and an Exploit-DB entry (30468) exists. No ransomware group is documented as using it.
What to do
- Upgrade RealPlayer to 17.0.4.61 or later on Windows and 12.0.1.1738 or later on Mac, per the vendor advisory.
- If patching is not possible, restrict or block opening of untrusted RMP files and disable RealPlayer file associations for RMP.
- Enforce email and web gateway filtering of RMP attachments and downloads from untrusted sources.
- Run RealPlayer with least privilege and consider application allowlisting to limit code execution impact.
Detection
- Monitor for RealPlayer processes spawning unexpected child processes or making outbound network connections after opening an RMP file.
- Hunt for RMP files with abnormally long version or encoding values in the XML declaration using file content inspection.
- Review endpoint logs for crashes or buffer-overflow-related exceptions in RealPlayer when processing media files.
- Correlate Exploit-DB 30468 indicators and known RMP delivery vectors in proxy and email logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-7260 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-7260), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.