VulnerabilityModified
CVE-2018-19592
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default.
HIGH 7.8EPSS 1.09%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.09% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-276
- Affected
- corsair/link
- Source
- cve@mitre.org
References
- http://forum.corsair.com/v3/showthread.php?t=155646Release Notes, Vendor Advisory
- https://github.com/BradyDonovan/CVE-2018-19592/blob/master/CLink4ServiceThird Party Advisory
- http://forum.corsair.com/v3/showthread.php?t=155646Release Notes, Vendor Advisory
- https://github.com/BradyDonovan/CVE-2018-19592/blob/master/CLink4ServiceThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.