{"api_version":"1","generated_at":"2026-07-23T14:33:38+00:00","cve":"CVE-2021-20726","urls":{"html":"https://cve.report/CVE-2021-20726","api":"https://cve.report/api/cve/CVE-2021-20726.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-20726","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-20726"},"summary":{"title":"CVE-2021-20726","description":"Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory.","state":"PUBLIC","assigner":"vultures@jpcert.or.jp","published_at":"2021-05-24 04:15:00","updated_at":"2022-05-03 16:04:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://www.overwolf.com/","name":"https://www.overwolf.com/","refsource":"MISC","tags":[],"title":"Overwolf | Development of gaming apps made easy","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://jvn.jp/en/jp/JVN78254777/index.html","name":"https://jvn.jp/en/jp/JVN78254777/index.html","refsource":"MISC","tags":[],"title":"JVN#78254777: Installer of Overwolf may insecurely load Dynamic Link Libraries","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-20726","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-20726","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"20726","vulnerable":"1","versionEndIncluding":"2.168.0.n","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"overwolf","cpe5":"overwolf","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2021-20726","ASSIGNER":"vultures@jpcert.or.jp","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Overwolf Ltd.","product":{"product_data":[{"product_name":"The Installer of Overwolf","version":{"version_data":[{"version_value":"2.168.0.n and earlier"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Untrusted search path vulnerability"}]}]},"references":{"reference_data":[{"url":"https://www.overwolf.com/","refsource":"MISC","name":"https://www.overwolf.com/"},{"url":"https://jvn.jp/en/jp/JVN78254777/index.html","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN78254777/index.html"}]},"description":{"description_data":[{"lang":"eng","value":"Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory."}]}},"nvd":{"publishedDate":"2021-05-24 04:15:00","lastModifiedDate":"2022-05-03 16:04:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.4},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:overwolf:overwolf:*:*:*:*:*:*:*:*","versionEndIncluding":"2.168.0.n","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"20726","Ordinal":"194771","Title":"CVE-2021-20726","CVE":"CVE-2021-20726","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"20726","Ordinal":"1","NoteData":"Untrusted search path vulnerability in The Installer of Overwolf 2.168.0.n and earlier allows an attacker to gain privileges and execute arbitrary code with the privilege of the user invoking the installer via a Trojan horse DLL in an unspecified directory.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"20726","Ordinal":"2","NoteData":"2021-05-23","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"20726","Ordinal":"3","NoteData":"2021-05-23","Type":"Other","Title":"Modified"}]}}}