I've seen rumor of another one, but I don't think EA/Respawn want that one proliferated. http://forum.smartlaunch.net/Topic26146-18-1.aspx. In order for us to fully understand how this exploit works, we need to understand how Windows treats custom URI schemes. We can exploit this behavior and load plugins remotely if we supply the platformpluginpath argument with a Windows share. I'm trying to control Origin via command line (mainly to launch specific games). This is where the iframe comes in. Sie können Argumente an die Main- Methode senden, indem Sie die Methode auf eine der folgenden Arten definieren:You can send arguments to the Main method by defining the method in one of the following ways: Sie müssen die Signatur von Main manuell in program.cs ändern, um in der Main-Methode in einer Windows Forms-Anwendung Befehlszeilenargumente zu aktivieren.To enable command-line arguments in the Main method in a Windows Forms application, you must manually modify the signature of Main in program.cs. Daher ist es sicher, ohne Überprüfung auf NULL auf die Length-Eigenschaft zuzugreifen.So, it's safe to access the Length property without null checking. Sie können auch Environment.CommandLine oder Environment.GetCommandLineArgs verwenden, um von einem beliebigen Punkt in einer Konsolen- oder Windows-Anwendung auf die Befehlszeilenargumente zuzugreifen.You can also use Environment.CommandLine or Environment.GetCommandLineArgs to access the command-line arguments from any point in a console or Windows application. TL;DR: Another Origin RCE, unrelated to CVE-2019-11354. Origin is written mainly using the Qt framework, which is what enticed me into trying these arguments. not sure if Origin has this implemented but there's a feature from Gmail (not sure if it's part of the API) that's commonly used in Rainmeter skins. It is installed through Origin. Der Parameter der Main-Methode ist ein String-Array, das die Befehlszeilenargumente darstellt.The parameter of the Main method is a String array that represents the command-line arguments. However, this vulnerability can be found in a number of other applications. Interestingly enough, shortcut files do not encode special characters, which is an issue on its own. This technique is hardly Origin specific. –r:1024x768 would set it to 1024x768] The full target field would look like this (depending on your installation folder: "C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe" -w -r:1024x768 Origin command line arguments As the last post on this blog clearly demonstrated, a poorly implemented custom URI can have a number of security concerns. However, for custom URIs that don't have encapsulated arguments in the registry, you can easily just inject arguments with a space. A command-line interface (CLI) processes commands to a computer program in the form of lines of text. Python List vs Array – 4 Differences to know! Reading Python Command-line arguments using the sys module 