CVE-2019-11354 EXPLOIT
7.8
HIGH · CVSS 3.1 · EPSS 23.1% (pctl 98)
Patch early
A public exploit exists.
Description
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Origin2 URI handler. This can be used to escape the underlying AngularJS sandbox and achieve remote code execution via an origin2://game/launch URL for QtApplication QDesktopServices communication.
Scoring
| CVSS | 7.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| EPSS | 23.13% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-74 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-04-19 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ea | origin |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | dotProject 2.1.9 - SQL Injection | 2019-06-24 |
References
- http://gamasutra.com/view/news/340907/A_nowfixed_Origin_vulnerability_potentially_opened_the_client_to_hackers.php
- http://packetstormsecurity.com/files/153375/dotProject-2.1.9-SQL-Injection.html
- http://packetstormsecurity.com/files/153485/EA-Origin-Template-Injection-Remote-Code-Execution.html
- https://blog.underdogsecurity.com/rce_in_origin_client/
- https://gizmodo.com/ea-origin-users-update-your-client-now-1834079604
- https://techcrunch.com/2019/04/16/ea-origin-bug-exposed-hackers/
- https://www.golem.de/news/sicherheitsluecke-ea-origin-fuehrte-schadcode-per-link-aus-1904-140738.html
- https://www.pcmag.com/news/367801/security-flaw-allowed-any-app-to-run-using-eas-origin-clien
- https://www.techradar.com/news/major-security-flaw-found-in-ea-origin-gaming-client
- https://www.thesun.co.uk/tech/8877334/sims-4-battlefield-fifa-origin-hackers/
- https://www.trustedreviews.com/news/time-update-origin-eas-game-client-security-risk-just-installed-3697942
- https://www.vg247.com/2019/04/17/ea-origin-security-flaw-run-malicious-code-fixed/
- http://gamasutra.com/view/news/340907/A_nowfixed_Origin_vulnerability_potentially_opened_the_client_to_hackers.php
- http://packetstormsecurity.com/files/153375/dotProject-2.1.9-SQL-Injection.html
- http://packetstormsecurity.com/files/153485/EA-Origin-Template-Injection-Remote-Code-Execution.html
- https://blog.underdogsecurity.com/rce_in_origin_client/
- https://gizmodo.com/ea-origin-users-update-your-client-now-1834079604
- https://techcrunch.com/2019/04/16/ea-origin-bug-exposed-hackers/
- https://www.golem.de/news/sicherheitsluecke-ea-origin-fuehrte-schadcode-per-link-aus-1904-140738.html
- https://www.pcmag.com/news/367801/security-flaw-allowed-any-app-to-run-using-eas-origin-clien
→ the Explorer · watch your stack · NVD