← volver
CVE-2011-10028highCWE-623

RealNetworks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution

36Vexday Risk Score

Corrige pronto. Ella tiene exploit funcional público.

ssvc Attendcvss 8.7epss 1.1%
de la publicación al arma0 días
Publicada en NVD20 ago
metasploit3 abr
probabilidad de explotación
1.1%top 37% de las CVE
explotación observada
noninguna fuente lo reporta
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N