PT-2025-4024 · Discord · Discord
Havook
·
Published
2025-01-27
·
Updated
2025-01-27
·
CVE-2025-0732
CVSS v2.0
3.5
Low
| Vector | AV:L/AC:H/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Discord versions up to 1.0.9177
Description
A problem has been found in Discord that affects some unknown functionality in the profapi.dll library, leading to an untrusted search path. The attack must be approached locally and has a rather high complexity, with difficult exploitation. The issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations
For versions up to 1.0.9177, as a temporary workaround, consider restricting access to the profapi.dll library until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Untrusted Search Path
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discord