Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4j5r-p7p6-v9j4

Опубликовано: 04 сент. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.

EPSS

Процентиль: 30%
0.00111
Низкий

7.8 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
nvd
больше 1 года назад

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.

EPSS

Процентиль: 30%
0.00111
Низкий

7.8 High

CVSS3

Дефекты

CWE-427