Epic Games Launcher
cpe:2.3:a:epicgames:launcher:*:*:*:*:*:*:*
- <= 17.2.1
A vulnerability allowing for an untrusted search path has been identified in the Epic Games Launcher, affecting versions prior to 17.2.1. This issue arises in the library profapi.dll within the Installer component, where unknown code is manipulated. The vulnerability requires local access to exploit, and the complexity of the attack is considered high, making exploitation difficult.
Exploitation of this vulnerability could lead to local privilege escalation by allowing an attacker to manipulate the search path, potentially leading to the execution of malicious code with elevated privileges.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.