CVE-2021-47852 HIGH

CVE-2021-47852: Rockstar Service - Insecure File Permissions

Vendor Rockstar Games
Product Rockstar Games Launcher
Weakness CWE-276
Published January 21, 2026
Last update January 22, 2026

CVSS base score

8.5/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Rockstar Games Launcher 1.0.37.349 contains a privilege escalation vulnerability that allows authenticated users to modify the service executable with weak permissions. Attackers can replace the RockstarService.exe with a malicious binary to create a new administrator user and gain elevated system access.

Key dates

02Disclosure timeline

January 21, 2026 CVE published
January 22, 2026 Record updated