CVE-2022-32271: Realnetworks Realplayer
Critical severity, CVSS 9.6. EPSS: 2.8% chance of exploitation in the next 30 days.
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.
Affected products
- Realnetworks Realplayer: version 20.0.8.310 only
Published 2022-06-03. Last modified 2026-06-17.