CVE-2019-11354
Summary
| CVE | CVE-2019-11354 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-04-19 22:29:00 UTC |
| Updated | 2022-04-18 17:08:00 UTC |
| Description | The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication. |
Risk And Classification
Problem Types: CWE-74
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| EA Origin Users, Update Your Client Now | MISC | gizmodo.com | Exploit, Third Party Advisory |
| Origin update fixes major vulnerability - VG247 | MISC | www.vg247.com | Third Party Advisory |
| dotProject 2.1.9 SQL Injection ≈ Packet Storm | MISC | packetstormsecurity.com | |
| EA Origin Template Injection Remote Code Execution ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Security flaw in EA’s Origin client exposed gamers to hackers – TechCrunch | MISC | techcrunch.com | Exploit, Third Party Advisory |
| Major security flaw found in EA Origin gaming client | TechRadar | MISC | www.techradar.com | Third Party Advisory |
| Security Flaw Allowed Any App to Run Using EA's Origin Client | MISC | www.pcmag.com | Third Party Advisory |
| Sims 4, Battlefield and Fifa players' computers could be taken over by hackers | MISC | www.thesun.co.uk | Third Party Advisory |
| RCE in EA's Origin Desktop Client – Underdog Security – Our blog... | MISC | blog.underdogsecurity.com | Exploit, Third Party Advisory |
| Gamasutra - A now-fixed Origin vulnerability potentially opened the client to hackers | MISC | gamasutra.com | Third Party Advisory |
| It's time to update Origin, as EA's game client is a security risk | MISC | www.trustedreviews.com | Third Party Advisory |
| Sicherheitslücke: EA Origin führte Schadcode per Link aus - Golem.de | MISC | www.golem.de | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.