Advisories

Rockstar Service - Insecure File Permissions

Go Back
severity
high
date
Affecting
  • Rockstar Games Launcher 1.0.37.349

CWE
  • CWE-276 Incorrect Default Permissions
CVSS
8.5
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Credit
George Tsimpidas
Description
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.