CVE-2018-12441
11.10.2018, 21:29
The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows "Everyone" group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.Enginsight
Vendor | Product | Version |
---|---|---|
corsair | corsair_utility_engine | 3.2.87 |
corsair | corsair_utility_engine | 3.3.103 |
corsair | corsair_utility_engine | 3.4.95 |
corsair | corsair_utility_engine | 3.6.109 |
corsair | corsair_utility_engine | 3.7.99 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration