Electronic Arts Dragon Age Origins Unquoted Service Path Vulnerability in DAUpdaterSVC

Vulnerability

A privilege escalation vulnerability has been identified in the DAUpdaterSVC service of Electronic Arts' Dragon Age Origins, version 1.05. The vulnerability arises from an unquoted service path and insecure permissions that allow local users to modify the executable path of the service. Since the service operates with NT AUTHORITY\SYSTEM privileges, this flaw can be exploited by replacing or adding a malicious executable in the service path, which will then be executed with full system rights when the service is started or restarted.

Impact

Exploitation of this vulnerability allows for remote code execution with NT AUTHORITY\SYSTEM privileges, leading to complete control over the affected system.

Reproduction

To reproduce this vulnerability, a local user must have access to a system with Dragon Age Origins installed. The user can then modify the DAUpdaterSVC service's executable path to include a malicious executable. Once the service is restarted, the malicious file will be executed with system privileges, allowing for unauthorized actions on the system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.6
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.