CVE-2021-47742

HIGH

Epic Games Psyonix Rocket League <=1.95 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Epic Games Psyonix Rocket League <=1.95 contains an insecure permissions vulnerability that allows authenticated users to modify executable files with full access permissions. Attackers can leverage the 'F' (Full) flag for the 'Authenticated Users' group to change executable files and potentially escalate system privileges.

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5650.php
Exploit, Third Party Advisory exploit
https://packetstormsecurity.com/files/162435
Third Party Advisory, VDB Entry vdb-entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/201128
Various Sources product
https://www.rocketleague.com/

Scores

CVSS v3 8.8
EPSS 0.0005
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Products (1)
Epic Games Inc./Epic Games Psyonix Rocket League <=1.95
Published Dec 31, 2025
Tracked Since Feb 18, 2026