A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
Advisories
Source ID Title
EUVD EUVD EUVD-2020-4743 A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T11:56:52.071Z

Reserved: 2020-04-28T00:00:00

Link: CVE-2020-12431

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-05-21T17:15:10.147

Modified: 2024-11-21T04:59:42.890

Link: CVE-2020-12431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.