In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.
Metrics
Affected Vendors & Products
References
History
Thu, 30 Jan 2025 22:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-428 | |
Metrics |
cvssV3_1
|
Mon, 27 Jan 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path. | |
References |
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-01-27T00:00:00.000Z
Updated: 2025-01-30T21:19:20.914Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57276

Updated: 2025-01-27T16:53:56.580Z

Status : Awaiting Analysis
Published: 2025-01-27T17:15:16.827
Modified: 2025-01-30T22:15:09.297
Link: CVE-2024-57276

No data.