Risk: High
Roxio's CinePlayer contains a buffer overflow vulnerability, which if exploited, could permit malicious users to execute arbitrary code on affected machines.
The vulnerability exists due to a boundary error in SonicDVDDashVRNav.dll and could be exploited by passing an overly long string to certain properties, causing a stack based buffer overflow and permitting arbitrary code execution.
As yet, Roxio has not issued a patch, but to prevent the flaw being exploited, CinePlayer users should set the kill-bit for the ActiveX control.