CVE-2013-2603: Use After Free
The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the (1) AddTag, (2) Ping, (3) QueuePause, (4) QueueRemove, (5) QueueTop, (6) RemoveTag, (7) TagRemoved, or (8) message method.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2603?
CVE-2013-2603 has a high severity rating due to the potential for remote code execution and denial of service.
How do I fix CVE-2013-2603?
To fix CVE-2013-2603, update the RealNetworks GameHouse RealArcade Installer to the latest version that addresses this vulnerability.
What are the risks associated with CVE-2013-2603?
The risks associated with CVE-2013-2603 include the potential for attackers to execute arbitrary code on affected systems.
Who is affected by CVE-2013-2603?
Users of RealNetworks GameHouse RealArcade Installer version 2.6.0.481 are directly affected by CVE-2013-2603.
What type of attack is possible with CVE-2013-2603?
CVE-2013-2603 allows for remote attackers to execute arbitrary code or cause a denial of service through unexpected type conversions.