A local privilege escalation is caused by Overwolf
loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an attacker with unprivileged
access to the system to run arbitrary code with SYSTEM privileges by placing a
malicious .dll file in the respective location.
            loading and executing certain dynamic link library files from a user-writeable
folder in SYSTEM context on launch. This allows an attacker with unprivileged
access to the system to run arbitrary code with SYSTEM privileges by placing a
malicious .dll file in the respective location.
Metrics
Affected Vendors & Products
Advisories
    | Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-48686 | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location. | 
Fixes
    Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
        | Link | Providers | 
|---|---|
| https://www.cirosec.de/sa/sa-2024-004 | 
                     | 
            
History
                    Wed, 04 Sep 2024 14:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Overwolf
         Overwolf overwolf  | 
|
| CPEs | cpe:2.3:a:overwolf:overwolf:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Overwolf
         Overwolf overwolf  | 
|
| Metrics | 
        
        ssvc
         
  | 
Wed, 04 Sep 2024 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location. | |
| Title | Local privilege escalation in Overwolf | |
| Weaknesses | CWE-427 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: cirosec
Published:
Updated: 2024-09-04T13:15:24.562Z
Reserved: 2024-08-15T07:21:21.987Z
Link: CVE-2024-7834
Updated: 2024-09-04T13:15:18.368Z
Status : Analyzed
Published: 2024-09-04T13:15:07.030
Modified: 2024-09-05T17:52:06.147
Link: CVE-2024-7834
No data.
                        OpenCVE Enrichment
                    No data.
 EUVD