A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-05-21T16:16:21
Updated: 2024-08-04T11:56:52.071Z
Reserved: 2020-04-28T00:00:00
Link: CVE-2020-12431
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-05-21T17:15:10.147
Modified: 2024-11-21T04:59:42.890
Link: CVE-2020-12431
Redhat
No data.