GameHouse RealArcade Installer contains a flaw in the StubbyUtil.ShellCtl.1 ActiveX in InstallerDlg.dll. The issue is triggered as the unsafe 'CopyDocument()' method allows copying arbitrary files to or from a user's system. With a specially crafted web page, a context-dependent attacker can disclose the contents of arbitrary files or execute arbitrary code.
Classification
Location:
Context Dependent
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality,
Loss of Integrity
Solution:
Workaround
Exploit:
Exploit Public
Disclosure:
RBS Confirmed,
Third-party Verified,
Uncoordinated Disclosure
OSVDB:
Web Related
Solution
Currently, there are no known upgrades or patches to correct this vulnerability. It is possible to correct the flaw by implementing the following workaround: set the kill-bit on the StubbyUtil.ShellCtl.1 ActiveX Control [ (CLSID {80AB3FB6-9660-416C-BE8D-0E2E8AC3138B}) ]. See Microsoft KB article 240797 for additional details.