Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h74-7h77-7f6p

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable.

The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable.

EPSS

Процентиль: 14%
0.00045
Низкий

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

The Gw2-64.exe in Guild Wars 2 launcher version 106916 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full Control) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable.

EPSS

Процентиль: 14%
0.00045
Низкий

Дефекты

CWE-276