Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-7834

Опубликовано: 04 сент. 2024
Источник: nvd
CVSS3: 7.8
CVSS3: 7.8
EPSS Низкий

Описание

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:overwolf:overwolf:*:*:*:*:*:*:*:*
Версия до 250.1.1 (исключая)

EPSS

Процентиль: 30%
0.00111
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-427
CWE-427

Связанные уязвимости

CVSS3: 7.8
github
больше 1 года назад

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.

EPSS

Процентиль: 30%
0.00111
Низкий

7.8 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-427
CWE-427