In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 30 Jan 2025 22:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Weaknesses | CWE-428 | |
| Metrics | 
        
        cvssV3_1
         
 
  | 
Mon, 27 Jan 2025 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | In Electronic Arts Dragon Age Origins 1.05, the DAUpdaterSVC service contains an unquoted service path vulnerability. This service is configured with insecure permissions, allowing users to modify the executable file path used by the service. The service runs with NT AUTHORITY\SYSTEM privileges, enabling attackers to escalate privileges by replacing or placing a malicious executable in the service path. | |
| References | 
         | 
Status: PUBLISHED
Assigner: mitre
Published: 2025-01-27T00:00:00.000Z
Updated: 2025-01-30T21:19:20.914Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57276
Updated: 2025-01-27T16:53:56.580Z
Status : Awaiting Analysis
Published: 2025-01-27T17:15:16.827
Modified: 2025-01-30T22:15:09.297
Link: CVE-2024-57276
No data.