← back
CVE-2011-10028highCWE-623

RealNetworks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution

36Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.7epss 1.1%
from disclosure to weapon0 days
Published on NVDAug 20
metasploitApr 3
exploitation probability
1.1%top 35% of all CVEs
observed exploitation
nono source reports it
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N