CVE Vulnerabilities

CVE-2020-27383

Improper Preservation of Permissions

Published: Jun 09, 2021 | Modified: Jun 17, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an Authenticated User to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the Authenticated Users Group which grants the (F) Flag aka Full Control

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Battle.net Blizzard 1.27.1.12428 (including) 1.27.1.12428 (including)

References