Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files with full access permissions. Attackers can leverage the 'F' (Full) flag for the 'Authenticated Users' group to change executable files and potentially escalate system privileges.
Metrics
Affected Vendors & Products
References
History
Mon, 05 Jan 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Epicgames
Epicgames psionix Rocket League |
|
| Vendors & Products |
Epicgames
Epicgames psionix Rocket League |
Fri, 02 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 31 Dec 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files with full access permissions. Attackers can leverage the 'F' (Full) flag for the 'Authenticated Users' group to change executable files and potentially escalate system privileges. | |
| Title | Epic Games Psyonix Rocket League <=1.95 Elevation of Privileges via Insecure Permissions | |
| Weaknesses | CWE-732 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-31T18:39:10.630Z
Updated: 2026-01-02T20:05:26.052Z
Reserved: 2025-12-31T02:09:17.952Z
Link: CVE-2021-47742
Updated: 2026-01-02T20:05:17.138Z
Status : Awaiting Analysis
Published: 2025-12-31T19:15:42.473
Modified: 2025-12-31T20:42:15.637
Link: CVE-2021-47742
No data.