vendor:
Rockstar Games Launcher
by:
George Tsimpidas
7.2
CVSS
HIGH
Elevation of Privileges
264
CWE
Product Name: Rockstar Games Launcher
Affected Version From: 1.0.37.349
Affected Version To: 1.0.37.349
Patch Exists: YES
Related CWE: N/A
CPE: //a:rockstar_games_launcher
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Home 10.0.18362 N/A Build 18362
2020
Rockstar Service – Insecure File Permissions
RockstarService.exe suffers from an elevation of privileges vulnerability which can be used by an 'Authenticated User' to modify the existing executable file of the service with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the 'Authenticated Users Group' which grants the (M) Flag aka 'Modify Privilege'.
Mitigation:
Restrict the permissions of the 'Authenticated Users Group' to prevent modification of the executable file.