← Back

CVE-2020-27383

nvd nist
Published: Jun 9, 2021Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

Affected (1)

Products: Blizzard: Battle.net
1 product
Battle.net
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.27.1.12428

Timeline

No history available yet.