Epic Games Launcher Untrusted Search Path Vulnerability in Installer Component

Vulnerability

A vulnerability allowing for an untrusted search path has been identified in the Epic Games Launcher, affecting versions prior to 17.2.1. This issue arises in the library profapi.dll within the Installer component, where unknown code is manipulated. The vulnerability requires local access to exploit, and the complexity of the attack is considered high, making exploitation difficult.

Impact

Exploitation of this vulnerability could lead to local privilege escalation by allowing an attacker to manipulate the search path, potentially leading to the execution of malicious code with elevated privileges.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
10.0
exploitability
3.0
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.