An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.
                
            References
                    | Link | Resource | 
|---|---|
| https://gist.github.com/sornram9254/4593dd5eb2bcca50d68dc6ac70e40b24 | Third Party Advisory | 
Configurations
                    History
                    03 Jun 2025, 13:52
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-05-21 16:15
Updated : 2025-06-03 13:52
NVD link : CVE-2025-27997
Mitre link : CVE-2025-27997
CVE.ORG link : CVE-2025-27997
JSON object : View
Products Affected
                blizzard
- battle.net
CWE
                
                    
                        
                        CWE-427
                        
            Uncontrolled Search Path Element
