CVE-2024-42052
28.07.2024, 03:15
The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a wevtutil.exe file in the folder.Enginsight
Vendor | Product | Version |
---|---|---|
splashtop | streamer | 𝑥 < 3.5.8.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References