CVE-2024-7834

CVSS V2 None CVSS V3 None
Description
A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.
Overview
  • CVE ID
  • CVE-2024-7834
  • Assigner
  • cirosec
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-04T12:35:27.628Z
  • Last Modified Date
  • 2024-09-04T13:15:24.562Z
References
Reference URL Reference Tags
https://www.cirosec.de/sa/sa-2024-004 third-party-advisory
History
Created Old Value New Value Data Type Notes
2024-09-05 13:05:43 Added to TrackCVE