A local privilege escalation is caused by Overwolf
loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an attacker with unprivileged
access to the system to run arbitrary code with SYSTEM privileges by placing a
malicious .dll file in the respective location.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.cirosec.de/sa/sa-2024-004 |
History
Wed, 04 Sep 2024 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Overwolf
Overwolf overwolf |
|
CPEs | cpe:2.3:a:overwolf:overwolf:*:*:*:*:*:*:*:* | |
Vendors & Products |
Overwolf
Overwolf overwolf |
|
Metrics |
ssvc
|
Wed, 04 Sep 2024 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location. | |
Title | Local privilege escalation in Overwolf | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: cirosec
Published: 2024-09-04T12:35:27.628Z
Updated: 2024-09-04T13:15:24.562Z
Reserved: 2024-08-15T07:21:21.987Z
Link: CVE-2024-7834
Vulnrichment
Updated: 2024-09-04T13:15:18.368Z
NVD
Status : Analyzed
Published: 2024-09-04T13:15:07.030
Modified: 2024-09-05T17:52:06.147
Link: CVE-2024-7834
Redhat
No data.