First published: Fri Apr 19 2019(Updated: )
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Electronic Arts Origin | =10.5.36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11354 is considered critical due to the potential for remote code execution.
To fix CVE-2019-11354, update to the latest version of Electronic Arts Origin, which resolves this vulnerability.
CVE-2019-11354 allows for template injection attacks that can lead to remote code execution.
CVE-2019-11354 specifically affects Electronic Arts Origin version 10.5.36 on Windows.
Exploiting CVE-2019-11354 can allow an attacker to escape the AngularJS sandbox and execute arbitrary code on the affected system.