PT-2015-3547 · Realnetworks · Realarcade Installer
Published
2015-01-12
·
Updated
2015-01-13
·
CVE-2013-2604
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RealNetworks GameHouse RealArcade Installer versions 2.6.0.481 through 3.0.7
Description
The issue concerns weak permissions set for the GameHouse Games directory tree, allowing local users to gain privileges. This can be achieved by placing a Trojan horse DLL in an individual game's directory. For example, a malicious DDRAW.DLL in the Zuma Deluxe directory could be used for exploitation.
Recommendations
For versions 2.6.0.481 through 3.0.7, consider restricting write access to the GameHouse Games directory tree to prevent unauthorized modifications.
As a temporary workaround, avoid using the affected GameHouse Games directory tree until a patch is available.
Restrict access to the directory tree to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Realarcade Installer