vendor:
Battle.Net
by:
Tulpa
7.5
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: Battle.Net
Affected Version From: 1.5.0.7963
Affected Version To: 1.5.0.7963
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10 Professional x64, Windows XP SP3 x86
2016
Battle.Net 1.5.0.7963 Local Privilege Escalation
Battle.Net installs with weak folder permissions granting any built-in user account with full permission to the contents of the directory and its subfolders. This allows an attacker an opportunity for their own code execution under any other user running the application.
Mitigation:
Ensure proper folder permissions are set for the Battle.Net directory and its subfolders.