PT-2015-3546 · Realnetworks · Realarcade Installer

Publicado

2015-01-12

·

Atualizado

2015-01-13

·

CVE-2013-2603

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RealArcade Installer version 2.6.0.481
Description The issue concerns the RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll, which performs unexpected type conversions for invalid parameter types. This allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to certain methods, including AddTag, Ping, QueuePause, QueueRemove, QueueTop, RemoveTag, TagRemoved, or message.
Recommendations For RealArcade Installer version 2.6.0.481, consider disabling the RACInstaller.StateCtrl.1 ActiveX control until a patch is available to prevent potential exploitation. Restrict access to the vulnerable methods to minimize the risk of arbitrary code execution or denial of service. Avoid using the affected methods in the ActiveX control until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2013-2603

Produtos afetados

Realarcade Installer