** DISPUTED ** TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. See reference document for more details.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/GitHubAssessments/CVE_Assessment_06_2019/blob/master/Snagit_Review.pdf | Exploit Third Party Advisory | 
| https://docs.google.com/document/d/1W33rsdISmexLOGS4VmLUIITRU_KqGULcij1Z6QyxsjU/edit?usp=sharing | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
                                
                                
 
  | 
                        
Information
                Published : 2021-07-26 13:15
Updated : 2022-01-01 09:55
NVD link : CVE-2020-18171
Mitre link : CVE-2020-18171
JSON object : View
CWE
                
                    
                        
                        CWE-269
                        
            Improper Privilege Management
Products Affected
                techsmith
- snagit
 
microsoft
- windows
 


