RealNetworks GameHouse 'InstallerDlg.dll' 2.6.0.445 ActiveX Control - Multiple Vulnerabilities

EDB-ID:

35560

CVE:

N/A

Author:

rgod

Type:

remote

Platform:

Windows

Published:

2011-04-03

source: http://www.securityfocus.com/bid/47133/info

GameHouse 'InstallerDlg.dll' ActiveX control is prone to multiple vulnerabilities.

Successfully exploiting these issues allows the attacker to execute arbitrary commands within the context of the application (typically, Internet Explorer) that uses the ActiveX control, and allows remote attackers to create or overwrite arbitrary local files and to execute arbitrary code. Failed exploit attempts will result in a denial-of-service condition.

InstallerDlg.dll 2.6.0.445 is vulnerable; other versions may also be affected. 

https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/35560-1.zip
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/35560-2.zip
https://github.com/offensive-security/exploitdb-bin-sploits/raw/master/bin-sploits/35560-3.rb