CVE-2011-10028
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 58.89%
- CWE
- CWE-623
- Published
- 2025-08-20
- Last modified
- 2026-05-15
Affected products
- RealNetworks RealArcade ActiveX
- RealNetworks RealArcade ActiveX
Weakness type
Related vulnerabilities
- CVE-2014-2368 — Advantech WebAccess Unsafe ActiveX Control Marked Safe For Scripting
- CVE-2018-17925 — Multiple instances of this vulnerability (Unsafe ActiveX Control Marked Safe For Scripting) have been identified in the