CVE-2013-2604: Realnetworks Realarcade Installer

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in the Zuma Deluxe directory.

Affected products

  • Realnetworks Realarcade Installer: version 2.6.0.481 only; version 3.0.7 only

Published 2015-01-12. Last modified 2026-06-16.