CVE-2018-6546
CVE-2018-6546
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.
Affected products
n/a · n/apublic PoCs found — 3
githubgithub.com/securifera/CVE-2018-6546-Exploit★ 41cve_referencewww.exploit-db.com/exploits/44476/unverifiedexploitdbwww.exploit-db.com/exploits/44476unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →