Record summary

CVE-2019-12828 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath argument supplied with a Windows network share.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBEA Origin < 10.5.38 - Remote Code ExecutionExploitDB exploitby Dominik PennerNot analyzed1 file
ExploitDB

PoC details

References

6