peter bassill · operator
$ cve CVE-2019-11354 JSON

CVE-2019-11354 EXPLOIT

7.8
HIGH · CVSS 3.1 · EPSS 23.1% (pctl 98)

Patch early

A public exploit exists.

Description

The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.

Scoring

CVSS7.8 (HIGH, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS23.13% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-74
On CISA KEVno
Public exploityes
Published2019-04-19
Last modified2026-06-17

Affected (1)

VendorProduct
eaorigin

Public exploits

SourceTitleDate
exploit-dbdotProject 2.1.9 - SQL Injection2019-06-24

References

→ the Explorer  ·  watch your stack  ·  NVD