Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqmr-qq67-c6hj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

EPSS

Процентиль: 14%
0.00045
Низкий

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 7.8
nvd
больше 4 лет назад

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

EPSS

Процентиль: 14%
0.00045
Низкий

Дефекты

CWE-281