vendor:
Battle.Net Desktop App
by:
George Tsimpidas
7.2
CVSS
HIGH
Insecure File Permissions
276
CWE
Product Name: Battle.Net Desktop App
Affected Version From: 1.27.1.12428
Affected Version To: 1.27.1.12428
Patch Exists: NO
Related CWE: N/A
CPE: a:blizzard_entertainment:battle.net_desktop_app
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Home 10.0.18362 N/A Build 18362
2020
Battle.Net 1.27.1.12428 – Insecure File Permissions
Battle.Net Launcher (Battle.net.exe) suffers from an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full) for 'Users' group, making the entire directory 'Battle.net' and its files and sub-dirs world-writable.
Mitigation:
The user should set the proper permissions to the directory and files of the application, so that only the user has the permission to modify the files.