header-logo
Suggest Exploit
vendor:
InstallerDlg.dll
by:
Unknown
7.5
CVSS
HIGH
Arbitrary Code Execution, File Overwrite, Denial of Service
CWE
Product Name: InstallerDlg.dll
Affected Version From: 2.6.0.445
Affected Version To: Unknown
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested:
Unknown

GameHouse ‘InstallerDlg.dll’ ActiveX Control Multiple Vulnerabilities

The GameHouse 'InstallerDlg.dll' ActiveX control is prone to multiple vulnerabilities. Successfully exploiting these issues allows the attacker to execute arbitrary commands within the context of the application that uses the ActiveX control. It also allows remote attackers to create or overwrite arbitrary local files and to execute arbitrary code. Failed exploit attempts will result in a denial-of-service condition.

Mitigation:

No known mitigation
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/47133/info

GameHouse 'InstallerDlg.dll' ActiveX control is prone to multiple vulnerabilities.

Successfully exploiting these issues allows the attacker to execute arbitrary commands within the context of the application (typically, Internet Explorer) that uses the ActiveX control, and allows remote attackers to create or overwrite arbitrary local files and to execute arbitrary code. Failed exploit attempts will result in a denial-of-service condition.

InstallerDlg.dll 2.6.0.445 is vulnerable; other versions may also be affected. 

https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/35560-1.zip
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/35560-2.zip
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/35560-3.rb