PT-2018-18305 · Displaylink · Displaylink Core Software Cleaner Application

Aleix Sala Bach

·

Published

2018-06-05

·

Updated

2018-08-01

·

CVE-2018-7884

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: DisplayLink Core Software Cleaner Application version 8.2.1956
Description: An issue was discovered in the DisplayLink Core Software Cleaner Application. When the drivers are updated to a newer version, the product launches a process as SYSTEM to uninstall the old version. This process, cl 1956.exe, is run as SYSTEM on the %systemroot%Temp folder, where any user can write a DLL (e.g., version.dll) to perform DLL Hijacking and elevate privileges to SYSTEM.
Recommendations: For DisplayLink Core Software Cleaner Application version 8.2.1956, as a temporary workaround, consider restricting write access to the %systemroot%Temp folder to minimize the risk of exploitation.

Fix

Untrusted Search Path

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-7884

Affected Products

Displaylink Core Software Cleaner Application