Description
Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.
Problem types
Product status
Credits
George Tsimpidas
References
www.exploit-db.com/exploits/49739 (ExploitDB-49739)
socialclub.rockstargames.com/rockstar-games-launcher (Rockstar Games Launcher Official Site)
www.vulncheck.com/...kstar-service-insecure-file-permissions (VulnCheck Advisory: Rockstar Service - Insecure File Permissions)