CVE-2025-1804
CVSS 3.1 Score 7 of 10 (high)
Details
Published Mar 1, 2025
Updated: Mar 7, 2025
CWE ID 427
CWE ID 426
Summary
CVE-2025-1804 is a critical vulnerability affecting Blizzard Battle.Net up to version 2.39.0.15212 on Windows. This issue lies within the unknown functionality of the profapi.dll library, leading to an uncontrolled search path. The attacker must initiate the exploit locally, making it a targeted threat. Despite the vendor's assessment of a low risk level, the complexity and difficulty of implementing the attack make it noteworthy and potentially dangerous.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Blizzard Battle.net
Affected Vendors
- Blizzard Entertainment