Products: 8
    Vulnerabilities: 12
    Known Exploited: 0
    0
    Critical Level Threats
    7
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-15914

    A cross-site scripting (XSS) vulnerability exists in the Origin Client for Mac and PC 10.5.86 or earlier that could allow a remote attacker to execute arbitrary Javascript in a target user’s Origin client. An attacker could use this vulnerability to access sensitive data related to the target user’s Origin account, or to control or monitor the Origin text chat window.

    Last Modified: Nov 21, 2024
    Published: Oct 30, 2020

    CVE-2020-27708

    A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System. Once the user has obtained elevated access, they may be able to take control of the system and perform actions otherwise reserved for high privileged users or system Administrators.

    Last Modified: Nov 21, 2024
    Published: Oct 30, 2020

    CVE-2019-19741

    Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248. When Origin.exe connects to the named pipe OriginClientService, the privileged service verifies the client's executable file instead of its in-memory process (which can be significantly different from the executable file due to, for example, DLL injection). Data transmitted over the pipe is encrypted using a static key. Instead of hooking the pipe communication directly via WriteFileEx(), this can be bypassed by hooking the EVP_EncryptUpdate() function of libeay32.dll. The pipe takes the command CreateDirectory to create a directory and adjust the directory DACL. Calls to this function can be intercepted, the directory and the DACL can be replaced, and the manipulated DACL is written. Arbitrary DACL write is further achieved by creating a hardlink in a user-controlled directory that points to (for example) a service binary. The DACL is then written to this service binary, which results in escalation of privileges.

    Last Modified: Nov 21, 2024
    Published: Feb 20, 2020

    CVE-2013-4867

    Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

    Last Modified: Nov 21, 2024
    Published: Dec 27, 2019

    CVE-2019-19248

    Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).

    Last Modified: Nov 21, 2024
    Published: Dec 12, 2019
    Items Per Page
    Ea Vulnerabilities & Security CVEs | CVE-DB