Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability
CVE-2024-11872

7.8HIGH

Key Information:

Vendor

Epic Games

Vendor
CVE Published:
12 December 2024

What is CVE-2024-11872?

The vulnerability in the Epic Games Launcher is a local privilege escalation issue stemming from incorrect default permissions set on a sensitive folder during the product installation process. This design flaw allows local attackers, who have already gained the ability to execute code with low privileges, to exploit the vulnerability. By leveraging this defect, an attacker can potentially escalate their privileges to execute arbitrary code with SYSTEM permissions, significantly compromising the integrity and security of the affected system. Users are advised to follow best security practices and apply any recommended updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Epic Games Launcher 16.6.0-33806133

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-11872 : Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability