CVE-2021-24030

CRITICAL

Facebook Gameroom <1.26.0 - Code Injection

Title source: llm
STIX 2.1

Description

The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allows a malicious URL to cause code execution. This issue affects versions prior to v1.26.0.

Scores

CVSS v3 9.8
EPSS 0.0116
EPSS Percentile 78.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-88
Status published
Products (1)
facebook/gameroom < 1.26.0
Published Mar 10, 2021
Tracked Since Feb 18, 2026