plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, executes code at a user-defined (local or SMB) path as SYSTEM when the execute_installer parameter is used in an HTTP message. This occurs without properly authenticating the user.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T06:10:10.171Z
Reserved: 2018-02-02T00:00:00
Link: CVE-2018-6546
No data.
Status : Modified
Published: 2018-04-13T16:29:01.063
Modified: 2024-11-21T04:10:52.650
Link: CVE-2018-6546
No data.
OpenCVE Enrichment
No data.
Weaknesses