{"api_version":"1","generated_at":"2026-07-23T15:29:54+00:00","cve":"CVE-2019-11354","urls":{"html":"https://cve.report/CVE-2019-11354","api":"https://cve.report/api/cve/CVE-2019-11354.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11354","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11354"},"summary":{"title":"CVE-2019-11354","description":"The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-04-19 22:29:00","updated_at":"2022-04-18 17:08:00"},"problem_types":["CWE-74"],"metrics":[],"references":[{"url":"https://gizmodo.com/ea-origin-users-update-your-client-now-1834079604","name":"https://gizmodo.com/ea-origin-users-update-your-client-now-1834079604","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"EA Origin Users, Update Your Client Now","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.vg247.com/2019/04/17/ea-origin-security-flaw-run-malicious-code-fixed/","name":"https://www.vg247.com/2019/04/17/ea-origin-security-flaw-run-malicious-code-fixed/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Origin update fixes major vulnerability - VG247","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/153375/dotProject-2.1.9-SQL-Injection.html","name":"http://packetstormsecurity.com/files/153375/dotProject-2.1.9-SQL-Injection.html","refsource":"MISC","tags":[],"title":"dotProject 2.1.9 SQL Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/153485/EA-Origin-Template-Injection-Remote-Code-Execution.html","name":"http://packetstormsecurity.com/files/153485/EA-Origin-Template-Injection-Remote-Code-Execution.html","refsource":"MISC","tags":[],"title":"EA Origin Template Injection Remote Code Execution ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://techcrunch.com/2019/04/16/ea-origin-bug-exposed-hackers/","name":"https://techcrunch.com/2019/04/16/ea-origin-bug-exposed-hackers/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Security flaw in EA’s Origin client exposed gamers to hackers – TechCrunch","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.techradar.com/news/major-security-flaw-found-in-ea-origin-gaming-client","name":"https://www.techradar.com/news/major-security-flaw-found-in-ea-origin-gaming-client","refsource":"MISC","tags":["Third Party Advisory"],"title":"Major security flaw found in EA Origin gaming client | TechRadar","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.pcmag.com/news/367801/security-flaw-allowed-any-app-to-run-using-eas-origin-clien","name":"https://www.pcmag.com/news/367801/security-flaw-allowed-any-app-to-run-using-eas-origin-clien","refsource":"MISC","tags":["Third Party Advisory"],"title":"Security Flaw Allowed Any App to Run Using EA's Origin Client","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.thesun.co.uk/tech/8877334/sims-4-battlefield-fifa-origin-hackers/","name":"https://www.thesun.co.uk/tech/8877334/sims-4-battlefield-fifa-origin-hackers/","refsource":"MISC","tags":["Third Party Advisory"],"title":"Sims 4, Battlefield and Fifa players' computers could be taken over by hackers","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.underdogsecurity.com/rce_in_origin_client/","name":"https://blog.underdogsecurity.com/rce_in_origin_client/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"RCE in EA's Origin Desktop Client – Underdog Security – Our blog...","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://gamasutra.com/view/news/340907/A_nowfixed_Origin_vulnerability_potentially_opened_the_client_to_hackers.php","name":"http://gamasutra.com/view/news/340907/A_nowfixed_Origin_vulnerability_potentially_opened_the_client_to_hackers.php","refsource":"MISC","tags":["Third Party Advisory"],"title":"Gamasutra - A now-fixed Origin vulnerability potentially opened the client to hackers","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.trustedreviews.com/news/time-update-origin-eas-game-client-security-risk-just-installed-3697942","name":"https://www.trustedreviews.com/news/time-update-origin-eas-game-client-security-risk-just-installed-3697942","refsource":"MISC","tags":["Third Party Advisory"],"title":"It's time to update Origin, as EA's game client is a security risk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.golem.de/news/sicherheitsluecke-ea-origin-fuehrte-schadcode-per-link-aus-1904-140738.html","name":"https://www.golem.de/news/sicherheitsluecke-ea-origin-fuehrte-schadcode-per-link-aus-1904-140738.html","refsource":"MISC","tags":["Third Party Advisory"],"title":"Sicherheitslücke: EA Origin führte Schadcode per Link aus - Golem.de","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11354","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11354","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11354","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ea","cpe5":"origin","cpe6":"10.5.36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"11354","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ea","cpe5":"origin","cpe6":"10.5.36","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-11354","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://blog.underdogsecurity.com/rce_in_origin_client/","refsource":"MISC","name":"https://blog.underdogsecurity.com/rce_in_origin_client/"},{"url":"https://techcrunch.com/2019/04/16/ea-origin-bug-exposed-hackers/","refsource":"MISC","name":"https://techcrunch.com/2019/04/16/ea-origin-bug-exposed-hackers/"},{"url":"http://gamasutra.com/view/news/340907/A_nowfixed_Origin_vulnerability_potentially_opened_the_client_to_hackers.php","refsource":"MISC","name":"http://gamasutra.com/view/news/340907/A_nowfixed_Origin_vulnerability_potentially_opened_the_client_to_hackers.php"},{"url":"https://www.thesun.co.uk/tech/8877334/sims-4-battlefield-fifa-origin-hackers/","refsource":"MISC","name":"https://www.thesun.co.uk/tech/8877334/sims-4-battlefield-fifa-origin-hackers/"},{"url":"https://gizmodo.com/ea-origin-users-update-your-client-now-1834079604","refsource":"MISC","name":"https://gizmodo.com/ea-origin-users-update-your-client-now-1834079604"},{"url":"https://www.pcmag.com/news/367801/security-flaw-allowed-any-app-to-run-using-eas-origin-clien","refsource":"MISC","name":"https://www.pcmag.com/news/367801/security-flaw-allowed-any-app-to-run-using-eas-origin-clien"},{"url":"https://www.techradar.com/news/major-security-flaw-found-in-ea-origin-gaming-client","refsource":"MISC","name":"https://www.techradar.com/news/major-security-flaw-found-in-ea-origin-gaming-client"},{"url":"https://www.trustedreviews.com/news/time-update-origin-eas-game-client-security-risk-just-installed-3697942","refsource":"MISC","name":"https://www.trustedreviews.com/news/time-update-origin-eas-game-client-security-risk-just-installed-3697942"},{"url":"https://www.vg247.com/2019/04/17/ea-origin-security-flaw-run-malicious-code-fixed/","refsource":"MISC","name":"https://www.vg247.com/2019/04/17/ea-origin-security-flaw-run-malicious-code-fixed/"},{"url":"https://www.golem.de/news/sicherheitsluecke-ea-origin-fuehrte-schadcode-per-link-aus-1904-140738.html","refsource":"MISC","name":"https://www.golem.de/news/sicherheitsluecke-ea-origin-fuehrte-schadcode-per-link-aus-1904-140738.html"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/153375/dotProject-2.1.9-SQL-Injection.html","url":"http://packetstormsecurity.com/files/153375/dotProject-2.1.9-SQL-Injection.html"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/153485/EA-Origin-Template-Injection-Remote-Code-Execution.html","url":"http://packetstormsecurity.com/files/153485/EA-Origin-Template-Injection-Remote-Code-Execution.html"}]}},"nvd":{"publishedDate":"2019-04-19 22:29:00","lastModifiedDate":"2022-04-18 17:08:00","problem_types":["CWE-74"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:ea:origin:10.5.36:*:*:*:*:windows:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11354","Ordinal":"149642","Title":"CVE-2019-11354","CVE":"CVE-2019-11354","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11354","Ordinal":"1","NoteData":"The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11354","Ordinal":"2","NoteData":"2019-04-19","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11354","Ordinal":"3","NoteData":"2019-07-01","Type":"Other","Title":"Modified"}]}}}