First published: Wed Mar 10 2021(Updated: )
The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.
Credit: cve-assign@fb.com
Affected Software | Affected Version | How to fix |
---|---|---|
<1.26.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Facebook Gameroom vulnerability is CVE-2021-24030.
The severity level of CVE-2021-24030 is critical with a score of 9.8.
CVE-2021-24030 allows a malicious URL to cause code execution in Facebook Gameroom.
Versions prior to v1.26.0 of Facebook Gameroom are affected by CVE-2021-24030.
To fix the CVE-2021-24030 vulnerability in Facebook Gameroom, upgrade to version v1.26.0 or later.