Description
Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of the WacomInstallI.txt file by the PrefUtil.exe utility. The issue results from incorrect permissions on the WacomInstallI.txt file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-16318.
Published: 2023-09-06
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-36430 Wacom Drivers for Windows Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Drivers for Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the WacomInstallI.txt file by the PrefUtil.exe utility. The issue results from incorrect permissions on the WacomInstallI.txt file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-16318.
History

Thu, 26 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Wacom drivers For Windows
CPEs cpe:2.3:a:wacom:drivers_for_windows:*:*:*:*:*:*:*:*
Vendors & Products Wacom drivers For Windows
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Microsoft Windows
Wacom Driver Drivers For Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2024-09-26T20:44:41.797Z

Reserved: 2023-05-03T20:10:47.062Z

Link: CVE-2023-32162

cve-icon Vulnrichment

Updated: 2024-08-02T15:10:23.879Z

cve-icon NVD

Status : Modified

Published: 2023-09-06T05:15:42.243

Modified: 2024-11-21T08:02:49.463

Link: CVE-2023-32162

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses