7.2
CVSSv2

CVE-2014-5453

Published: 25/08/2014 Updated: 26/08/2014
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Ubisoft Uplay PC prior to 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local users to gain privileges via a Trojan horse file.

Vulnerable Product Search on Vulmon Subscribe to Product

ubi uplay pc

ubi uplay pc 4.5.2.3010

Exploits

Ubisoft Uplay 46 Insecure File Permissions Local Privilege Escalation Vendor: Ubisoft Entertainment SA Product web page: wwwubicom Affected version: 463208 (PC) 4523010 (PC) Summary: Uplay is a digital distribution, digital rights management, multiplayer and communications service created by Ubisoft to provid ...