Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability
CVE-2024-11872
7.8HIGH
What is CVE-2024-11872?
The vulnerability in the Epic Games Launcher is a local privilege escalation issue stemming from incorrect default permissions set on a sensitive folder during the product installation process. This design flaw allows local attackers, who have already gained the ability to execute code with low privileges, to exploit the vulnerability. By leveraging this defect, an attacker can potentially escalate their privileges to execute arbitrary code with SYSTEM permissions, significantly compromising the integrity and security of the affected system. Users are advised to follow best security practices and apply any recommended updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Epic Games Launcher 16.6.0-33806133
