vendor:
Guild Wars 2
by:
George Tsimpidas
7.2
CVSS
HIGH
Insecure File Permissions
276
CWE
Product Name: Guild Wars 2
Affected Version From: 106915
Affected Version To: 106915
Patch Exists: NO
Related CWE: N/A
CPE: a:arena_net:guild_wars_2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Microsoft Windows 10 Home 10.0.18362 N/A Build 18362
2020
Guild Wars 2 – Insecure Folder Permissions
Guild Wars 2 Launcher (Gw2-64.exe) suffers from an elevation of privileges vulnerability which can be used by a simple user that can change the executable file with a binary of choice. The vulnerability exist due to the improper permissions, with the 'F' flag (Full) for 'Everyone' group, making the entire directory 'Guild Wars 2' and its files and sub-dirs world-writable.
Mitigation:
Ensure that the permissions of the Guild Wars 2 directory are properly set and that only authorized users have access to it.