Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hjw-6q7q-jc3c

Опубликовано: 20 авг. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7

Описание

The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.

The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.

EPSS

Процентиль: 98%
0.58889
Средний

8.7 High

CVSS4

Дефекты

CWE-623

Связанные уязвимости

nvd
6 месяцев назад

The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.

EPSS

Процентиль: 98%
0.58889
Средний

8.7 High

CVSS4

Дефекты

CWE-623