// For flags

CVE-2010-4235

RealNetworks Helix Server x-wap-profile Format String Remote Code Execution Vulnerability

Severity Score

10.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.

Vulnerabilidad de formato de cadena en RealNetworks Helix Server v12.x, v13.x, y v14.x antes de v14.2, y Helix Mobile Server v12.x, v13.x, y v14.x antes de 14.2, permite a atacantes remotos ejecutar código de su elección a través de vectores relacionado con el encabezado HTTP x-wap-perfil.

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Helix Server products. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the rmserver.exe process. This process is active by default on all Helix Server installations. Due to a failure to properly sanitize the contents of the 'x-wap-profile' header, it is possible to provide malicious data that is passed directly to a format string function. Remote attackers could leverage this vulnerability to execute arbitrary code under the context of the SYSTEM user.

*Credits: defrost
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2010-11-11 CVE Reserved
  • 2011-04-01 CVE Published
  • 2024-09-16 CVE Updated
  • 2024-09-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-134: Use of Externally-Controlled Format String
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Realnetworks
Search vendor "Realnetworks"
Helix Server
Search vendor "Realnetworks" for product "Helix Server"
12.0.0
Search vendor "Realnetworks" for product "Helix Server" and version "12.0.0"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Server
Search vendor "Realnetworks" for product "Helix Server"
12.0.1
Search vendor "Realnetworks" for product "Helix Server" and version "12.0.1"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Server
Search vendor "Realnetworks" for product "Helix Server"
13.0.0
Search vendor "Realnetworks" for product "Helix Server" and version "13.0.0"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Server
Search vendor "Realnetworks" for product "Helix Server"
13.1.1
Search vendor "Realnetworks" for product "Helix Server" and version "13.1.1"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Server
Search vendor "Realnetworks" for product "Helix Server"
14.0.0
Search vendor "Realnetworks" for product "Helix Server" and version "14.0.0"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Server
Search vendor "Realnetworks" for product "Helix Server"
14.0.1
Search vendor "Realnetworks" for product "Helix Server" and version "14.0.1"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Mobile Server
Search vendor "Realnetworks" for product "Helix Mobile Server"
12.0
Search vendor "Realnetworks" for product "Helix Mobile Server" and version "12.0"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Mobile Server
Search vendor "Realnetworks" for product "Helix Mobile Server"
13.1.1
Search vendor "Realnetworks" for product "Helix Mobile Server" and version "13.1.1"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Mobile Server
Search vendor "Realnetworks" for product "Helix Mobile Server"
14.0.0
Search vendor "Realnetworks" for product "Helix Mobile Server" and version "14.0.0"
-
Affected
Realnetworks
Search vendor "Realnetworks"
Helix Mobile Server
Search vendor "Realnetworks" for product "Helix Mobile Server"
14.0.1
Search vendor "Realnetworks" for product "Helix Mobile Server" and version "14.0.1"
-
Affected