PT-2024-29712 · Splashtop · Splashtop Streamer

Published

2024-07-28

·

Updated

2024-09-19

·

CVE-2024-42052

CVSS v3.1

7.8

High

VectorAC:L/AV:L/A:H/C:H/I:H/PR:L/S:U/UI:N
Name of the Vulnerable Software and Affected Versions Splashtop Streamer for Windows versions prior to 3.5.8.0
Description The issue concerns the MSI installer for Splashtop Streamer for Windows, which uses a temporary folder with weak permissions during installation. A local user can exploit this weakness to escalate privileges to SYSTEM by placing a wevtutil.exe file in the folder.
Recommendations For versions prior to 3.5.8.0, update to version 3.5.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the temporary folder used during installation to minimize the risk of exploitation.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-42052

Affected Products

Splashtop Streamer