PT-2024-29711 · Splashtop · Splashtop Streamer

Published

2024-07-28

·

Updated

2025-09-03

·

CVE-2024-42051

CVSS v3.1

7.8

High

VectorAC:L/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Splashtop Streamer for Windows versions prior to 3.6.2.0
Description The MSI installer for Splashtop Streamer for Windows uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.
Recommendations For versions prior to 3.6.2.0, update to version 3.6.2.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary folder used during installation to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-42051

Affected Products

Splashtop Streamer