ID:6013 - Exploit for Data Handling in Origin Client - CVE-2019-12828

 
Main Vulnerability Database Exploits ID:6013 - Exploit for Data Handling in Origin Client - CVE-2019-12828

ID:6013 - Exploit for Data Handling in Origin Client - CVE-2019-12828

Published: June 17, 2021


Vulnerability identifier: #VU31040
Vulnerability risk: High
CVE-ID: CVE-2019-12828
CWE-ID: CWE-19
Exploitation vector: Remote access
Vulnerable software:
Origin Client

Link to public exploit:


Vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

An issue was discovered in Electronic Arts Origin before 10.5.39. Due to improper sanitization of the origin:// and origin2:// URI schemes, it is possible to inject additional arguments into the Origin process and ultimately leverage code execution by loading a backdoored Qt plugin remotely via the platformpluginpath argument supplied with a Windows network share.


Remediation

Install update from vendor's website.