Vulnerabilities > EA > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-02 CVE-2020-27708 Improper Privilege Management vulnerability in EA Origin
A vulnerability exists in the Origin Client that could allow a non-Administrative user to elevate their access to either Administrator or System.
local
low complexity
ea CWE-269
7.2
2020-02-20 CVE-2019-19741 Unspecified vulnerability in EA Origin 10.5.36/10.5.55.33574
Electronic Arts Origin 10.5.55.33574 is vulnerable to local privilege escalation due to arbitrary directory DACL manipulation, a different issue than CVE-2019-19247 and CVE-2019-19248.
local
low complexity
ea
7.8
2019-12-12 CVE-2019-19248 Unspecified vulnerability in EA Origin 10.5.36/10.5.37/10.5.55.33574
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 2 of 2).
local
low complexity
ea
7.2
2019-12-12 CVE-2019-19247 Unspecified vulnerability in EA Origin
Electronic Arts Origin through 10.5.x allows Elevation of Privilege (issue 1 of 2).
local
low complexity
ea
7.2
2009-04-21 CVE-2008-6737 Information Exposure vulnerability in EA Crysis 1.1/1.2
Crysis 1.21 and earlier allows remote attackers to obtain sensitive player information such as real IP addresses by sending a keyexchange packet without a previous join packet, which causes Crysis to send a disconnect packet that includes unrelated log information.
network
low complexity
ea CWE-200
7.8