CVE-2013-2604: High severity realnetworks realarcade vulnerability
RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in the Zuma Deluxe directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2604?
CVE-2013-2604 is classified as a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2013-2604?
To mitigate CVE-2013-2604, review and modify the permissions on the GameHouse Games directory to restrict access.
Who is affected by CVE-2013-2604?
Users of RealNetworks GameHouse RealArcade Installer versions 2.6.0.481 and 3.0.7 are affected by CVE-2013-2604.
What is the impact of CVE-2013-2604?
The impact of CVE-2013-2604 allows local users to execute a Trojan horse DLL, potentially leading to unauthorized privileges.
Is there a patch available for CVE-2013-2604?
No official patch has been released for CVE-2013-2604; users should adjust directory permissions as a workaround.