ZDI-CAN-7241: Epic Games Launcher Protocol Command Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Visual Studio with tools for Unreal Engine development installed. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handler for the com.epicgames.launcher protocol. A crafted URI with the com.epicgames.launcher protocol can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of the current user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-7241?
The severity of ZDI-CAN-7241 is critical due to the potential for remote code execution.
How do I fix ZDI-CAN-7241?
To fix ZDI-CAN-7241, ensure that you apply the latest security updates provided by Microsoft for Visual Studio.
What software is affected by ZDI-CAN-7241?
ZDI-CAN-7241 affects installations of Microsoft Visual Studio with tools for Unreal Engine development installed.
Is user interaction required to exploit ZDI-CAN-7241?
Yes, user interaction is required for exploiting ZDI-CAN-7241 as the target must visit a malicious page.
What type of attacks can occur due to ZDI-CAN-7241?
ZDI-CAN-7241 can allow remote attackers to execute arbitrary code on the vulnerable system.