CVE Vulnerabilities

CVE-2013-2604

Published: Jan 12, 2015 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual games directory, as demonstrated by DDRAW.DLL in the Zuma Deluxe directory.

Affected Software

NameVendorStart VersionEnd Version
Realarcade_installerRealnetworks2.6.0.481 (including)2.6.0.481 (including)
Realarcade_installerRealnetworks3.0.7 (including)3.0.7 (including)

References