Описание
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.
Ссылки
- Third Party Advisory
- Release Notes
- Third Party Advisory
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 3.6.2.0 (исключая)
cpe:2.3:a:splashtop:streamer:*:*:*:*:-:windows:*:*
EPSS
Процентиль: 11%
0.00037
Низкий
7.8 High
CVSS3
Дефекты
CWE-1391
Связанные уязвимости
CVSS3: 7.8
github
больше 1 года назад
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.
EPSS
Процентиль: 11%
0.00037
Низкий
7.8 High
CVSS3
Дефекты
CWE-1391