In the client in Overwolf 0.149.2.30, a channel can be accessed or influenced by an actor that is not an endpoint.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25214
Reference (s):
- https://github.com/immunityinc/Advisories/blob/master/2020/CVE-2020-25214.pdf