CVE-2025-61973 Details
Description
A local privilege escalation vulnerability exists during the installation of Epic Games Store via the Microsoft Store. A low-privilege user can replace a DLL file during the installation process, which may result in unintended elevation of privileges.
A local privilege escalation vulnerability has been identified in the Epic Games Store when installed through the Microsoft Store. This issue allows low-privilege users to replace a DLL file during the installation, potentially leading to unauthorized elevation of privileges. The vulnerability arises because the temporary folder used during installation is writable by standard users, enabling the replacement of a legitimate DLL with a malicious one that is executed with SYSTEM privileges.
Users are advised to uninstall the Epic Games Store version 14.6.2.0 installed via the Microsoft Store and download the application directly from the Epic Games Store website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 15, 2026CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2279 | CVE | |
| https://talosintelligence.com/vulnerability_reports/TALOS-2025-2279 | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Epic Games Store | All versions |
CPE
Remediation
| |
| DXSETUP.exe | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | CVE Modified | CVE |
| Jan 15, 2026 | New CVE Received | [email protected] |
Volerion