module

Real Networks Arcade Games StubbyUtil.ProcessMgr ActiveX Arbitrary Code Execution

Disclosed
Apr 3, 2011
Created
May 30, 2018

Description

This module exploits a vulnerability in Real Networks Arcade Game's ActiveX control. The "exec"
function found in InstallerDlg.dll (v2.6.0.445) allows remote attackers to run arbitrary commands
on the victim machine.

Authors

rgod
sinn3r sinn3r@metasploit.com

Platform

Windows

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use exploit/windows/browser/real_arcade_installerdlg
msf exploit(real_arcade_installerdlg) > show targets
...targets...
msf exploit(real_arcade_installerdlg) > set TARGET < target-id >
msf exploit(real_arcade_installerdlg) > show options
...show and set options...
msf exploit(real_arcade_installerdlg) > exploit

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.