VulnerabilityAnalyzed
CVE-2024-42051
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation.
HIGH 7.8EPSS 0.15%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.15%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.15% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1391
- Affected
- splashtop/streamer
- Source
- cve@mitre.org
References
- https://github.com/SpacePlant/Vulns/blob/main/Advisories/2024/3.mdThird Party Advisory
- https://support-splashtopbusiness.splashtop.com/hc/en-us/articles/20716875636763-Splashtop-Streamer-version-v3-6-2-0-for-Windows-releasedRelease Notes
- https://github.com/SpacePlant/Vulns/blob/main/Advisories/2024/3.mdThird Party Advisory
- https://support-splashtopbusiness.splashtop.com/hc/en-us/articles/20716875636763-Splashtop-Streamer-version-v3-6-2-0-for-Windows-releasedRelease Notes
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.