vendor:
Plays TV Service
by:
7.5
CVSS
HIGH
Arbitrary File Execution
CWE
Product Name: Plays TV Service
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
Arbitrary File Execution in Raptr, Inc Plays TV Service
The Raptr, Inc Plays TV Service installation process on Windows allows for arbitrary file execution by writing uncontrolled data using the /extract_files path. This can be exploited by an attacker with SYSTEM privileges to execute arbitrary files on the target system.
Mitigation:
To mitigate this vulnerability, users should avoid installing or running the Raptr, Inc Plays TV Service. If already installed, users should uninstall the service immediately.