CVE-2024-7834

A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.
References
Link Resource
https://www.cirosec.de/sa/sa-2024-004 Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:overwolf:overwolf:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-09-04 13:15

Updated : 2024-09-05 17:52


NVD link : CVE-2024-7834

Mitre link : CVE-2024-7834

CVE.ORG link : CVE-2024-7834


JSON object : View

Products Affected

overwolf

  • overwolf
CWE
CWE-427

Uncontrolled Search Path Element