Files
CVEs-PoC/2020/CVE-2020-12431.md
T
2024-05-25 21:48:12 +02:00

18 lines
934 B
Markdown

### [CVE-2020-12431](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-12431)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
### POC
#### Reference
- https://improsec.com/tech-blog/privilege-escalation-vulnerability-in-splashtop-streamer
#### Github
No PoCs found on GitHub currently.