← volver
CVE-2011-10028

RealNetworks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution

CVSS 8.7 HIGHEPSS 1.1%CWE-623
Vexday Risk Score
36Atención
Decisión SSVC (CISA)
Attend
PoC disponible → seguir de cerca
CVSS 8.7EPSS 1.1%KEV nãoPoC Nuclei Metasploit simPatch
Ciclo de vida
03 abr 2011Exploit Metasploit disponible
20 ago 2025Publicada en NVD
Recomendación: Planificar corrección próxima — ya existe PoC pública.
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →