PT-2018-18305 · Displaylink · Displaylink Core Software Cleaner Application

Aleix Sala Bach

·

Publicado

2018-06-05

·

Atualizado

2018-08-01

·

CVE-2018-7884

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: DisplayLink Core Software Cleaner Application version 8.2.1956
Description: An issue was discovered in the DisplayLink Core Software Cleaner Application. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version. This process, cl 1956.exe, is run as SYSTEM on the %systemroot%Temp folder, where any user can write a DLL (e.g., version.dll) to perform DLL Hijacking and elevate privileges to SYSTEM.
Recommendations: For DisplayLink Core Software Cleaner Application version 8.2.1956, as a temporary workaround, consider restricting write access to the %systemroot%Temp folder to minimize the risk of exploitation.

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7884

Produtos afetados

Displaylink Core Software Cleaner Application