SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-19592

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default.

HIGH 7.8EPSS 1.09%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.09%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.09% probability · 63th percentile
CISA KEV
Not listed
Weakness
CWE-276
Affected
corsair/link
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.