CVE-2025-1804

A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor assigns this issue a low risk level.
Configurations

No configuration.

History

07 Mar 2025, 20:15

Type Values Removed Values Added
Summary
  • (es) Se ha detectado una vulnerabilidad en Blizzard Battle.Net hasta la versión 2.39.0.15212 en Windows y se ha clasificado como crítica. Este problema afecta a una funcionalidad desconocida en la librería profapi.dll. La manipulación conduce a una ruta de búsqueda no controlada. El ataque debe abordarse localmente. La complejidad de un ataque es bastante alta. Se sabe que su explotación es difícil.
Summary (en) A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. (en) A vulnerability was found in Blizzard Battle.Net up to 2.39.0.15212 on Windows and classified as critical. Affected by this issue is some unknown functionality in the library profapi.dll. The manipulation leads to uncontrolled search path. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation is known to be difficult. The vendor assigns this issue a low risk level.

01 Mar 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-01 19:15

Updated : 2025-03-07 20:15


NVD link : CVE-2025-1804

Mitre link : CVE-2025-1804

CVE.ORG link : CVE-2025-1804


JSON object : View

Products Affected

No product.

CWE
CWE-426

Untrusted Search Path

CWE-427

Uncontrolled Search Path Element