Описание
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.
Ссылки
- Third Party Advisory
- Release Notes
- Third Party Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 3.7.0.0 (исключая)
cpe:2.3:a:splashtop:streamer:*:*:*:*:-:windows:*:*
EPSS
Процентиль: 11%
0.00037
Низкий
7 High
CVSS3
Дефекты
CWE-269
Связанные уязвимости
CVSS3: 7
github
больше 1 года назад
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.
EPSS
Процентиль: 11%
0.00037
Низкий
7 High
CVSS3
Дефекты
CWE-269