PT-2019-13303 · Techsmith · Techsmith Relay Classic Recorder+1
Publicado
2019-07-10
·
Atualizado
2020-08-24
·
CVE-2019-13382
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SnagIT versions 12.4.1 through 2019.1.2
TechSmith Relay Classic Recorder versions prior to 5.2.1
Description
The issue allows for elevation of privilege by placing an invalid presentation file in a specific directory and then creating a symbolic link that points to an arbitrary folder with an arbitrary file name. This can be achieved by exploiting the UploaderService in SnagIT. The vulnerability was introduced in SnagIT Windows version 12.4.1.
Recommendations
For SnagIT versions 12.4.1 through 2019.1.2, update to a version later than 2019.1.2 to resolve the issue.
For TechSmith Relay Classic Recorder versions prior to 5.2.1, update to version 5.2.1 or later to fix the vulnerability.
As a temporary workaround, consider restricting access to the %PROGRAMDATA%TechSmithTechSmith RecorderQueuedPresentations and %PROGRAMDATA%TechsmithTechSmith RecorderInvalidPresentations directories to minimize the risk of exploitation.
Exploit
Correção
Link Following
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Snagit
Techsmith Relay Classic Recorder