← Back to CVE List

CVE-2018-6547

Published: 2018-04-13T16:29Z
Last Modified: 2024-11-21T04:10Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
plays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products, contains an HTTP message parsing function that takes a user-defined path and writes non-user controlled data as SYSTEM to the file when the extract_files parameter is used. This occurs without properly authenticating the user. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt