loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an attacker with unprivileged
access to the system to run arbitrary code with SYSTEM privileges by placing a
malicious .dll file in the respective location.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-48686 | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location. |
| Link | Providers |
|---|---|
| https://www.cirosec.de/sa/sa-2024-004 |
|
Wed, 04 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Overwolf
Overwolf overwolf |
|
| CPEs | cpe:2.3:a:overwolf:overwolf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Overwolf
Overwolf overwolf |
|
| Metrics |
ssvc
|
Wed, 04 Sep 2024 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location. | |
| Title | Local privilege escalation in Overwolf | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cirosec
Published:
Updated: 2024-09-04T13:15:24.562Z
Reserved: 2024-08-15T07:21:21.987Z
Link: CVE-2024-7834
Updated: 2024-09-04T13:15:18.368Z
Status : Analyzed
Published: 2024-09-04T13:15:07.030
Modified: 2024-09-05T17:52:06.147
Link: CVE-2024-7834
No data.
OpenCVE Enrichment
No data.
EUVD