CVE-2011-10028 Details
Description
The RealNetworks RealArcade platform includes an ActiveX control (InstallerDlg.dll, version 2.6.0.445) that exposes a method named Exec via the StubbyUtil.ProcessMgr COM object. This method allows remote attackers to execute arbitrary commands on a victim's Windows machine without proper validation or restrictions. This platform was sometimes referred to or otherwise known as RealArcade or Arcade Games and has since consolidated with RealNetworks' platform, GameHouse.
A vulnerability exists in the RealNetworks RealArcade platform's ActiveX control, specifically in InstallerDlg.dll version 2.6.0.445. This vulnerability allows remote attackers to execute arbitrary commands on a victim's Windows machine by exploiting the Exec method of the StubbyUtil.ProcessMgr COM object. The issue arises from inadequate validation and restrictions in the ActiveX control, which is marked safe for scripting and initialization, enabling exploitation through Internet Explorer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 20, 2025CISA-ADP
Assessed Aug 21, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-623 | Unsafe ActiveX Control Marked Safe For Scripting | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RealNetworks RealArcade | <= 2.6.0.445 |
CPE
Remediation
| |
| RealNetworks GameHouse | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Jun 16, 2026 | CVE Modified | CISA-ADP |
| Aug 21, 2025 | CVE Modified | CISA-ADP |
| Aug 20, 2025 | New CVE Received | [email protected] |
Volerion