Vulnerabilities
Vulnerable Software
Overwolf:  >> Overwolf  Security Vulnerabilities
A local privilege escalation is caused by Overwolf loading and executing certain dynamic link library files from a user-writeable folder in SYSTEM context on launch. This allows an attacker with unprivileged access to the system to run arbitrary code with SYSTEM privileges by placing a malicious .dll file in the respective location.
CVSS Score
7.8
EPSS Score
0.0
Published
2024-09-04
Overwolf Client 0.169.0.22 allows XSS, with resultant Remote Code Execution, via an overwolfstore:// URL.
CVSS Score
9.6
EPSS Score
0.125
Published
2021-07-19
Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory.
CVSS Score
7.8
EPSS Score
0.001
Published
2021-05-24
In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.
CVSS Score
8.1
EPSS Score
0.004
Published
2020-10-16
Overwolf before 0.149.2.30 mishandles Symbolic Links during updates, causing elevation of privileges.
CVSS Score
8.8
EPSS Score
0.005
Published
2020-07-24


Contact Us

Shodan ® - All rights reserved