CVE-2024-42050
28.07.2024, 03:15
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.Enginsight
Vendor | Product | Version |
---|---|---|
splashtop | streamer | 𝑥 < 3.7.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References