CVE-2024-7834

Published Sep 4, 2024

Last updated 2 months ago

Overview

Description
A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.
Source
a341c0d1-ebf7-493f-a84e-38cf86618674
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-427
a341c0d1-ebf7-493f-a84e-38cf86618674
CWE-427

Social media

Hype score
Not currently trending

Configurations