CVE-2011-2950 is a heap-based buffer overflow in qcpfformat.dll, the QCP-format handling component of RealNetworks RealPlayer. It affects RealPlayer versions 11.0 through 11.1 and 14.0.0 through 14.0.5, and RealPlayer SP versions 1.0 through 1.1.5. A crafted QCP file can trigger the overflow and permit remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (realplayer_qcp.rb) that exploits a heap overflow vulnerability (CVE-2011-2950) in RealNetworks RealPlayer's qcpfformat.dll when parsing specially crafted .QCP files. The exploit is delivered via a malicious HTTP server that serves both a crafted HTML/JavaScript page and a malicious .QCP file. The JavaScript performs a heap spray to position the attacker's payload in memory, and the .QCP file triggers the overflow when opened by the vulnerable RealPlayer ActiveX control in Internet Explorer 6 or 7 on Windows XP. The module allows the attacker to execute arbitrary code in the context of the browser, with payloads fully customizable via the Metasploit framework. The code is weaponized, supporting payload selection and JavaScript obfuscation. The only endpoints are the HTTP paths used to serve the exploit and trigger file. The repository is structured as a single Ruby file, typical for Metasploit modules, and leverages both Ruby and embedded JavaScript for exploit delivery.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.