Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-27383

Опубликовано: 09 июн. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 4.6
EPSS Низкий

Описание

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:blizzard:battle.net:1.27.1.12428:*:*:*:*:*:*:*

EPSS

Процентиль: 14%
0.00045
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-281

Связанные уязвимости

github
больше 3 лет назад

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

EPSS

Процентиль: 14%
0.00045
Низкий

7.8 High

CVSS3

4.6 Medium

CVSS2

Дефекты

CWE-281