Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-398q-xwvh-4mpj

Опубликовано: 27 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.3

Описание

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.

EPSS

Процентиль: 8%
0.00031
Низкий

7.3 High

CVSS3

Дефекты

CWE-428

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 года назад

In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.

EPSS

Процентиль: 8%
0.00031
Низкий

7.3 High

CVSS3

Дефекты

CWE-428