CVE-2020-12431

A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:splashtop:software_updater:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:splashtop:streamer:*:*:*:*:-:windows:*:*
cpe:2.3:a:splashtop:streamer:*:*:*:*:business:windows:*:*

Information

Published : 2020-05-21 10:15

Updated : 2021-07-21 04:39


NVD link : CVE-2020-12431

Mitre link : CVE-2020-12431


JSON object : View

CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

Advertisement

dedicated server usa

Products Affected

splashtop

  • streamer
  • software_updater