CVE-2020-12431: Medium severity splashtop vulnerability
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-12431?
CVE-2020-12431 is a Windows privilege change issue discovered in Splashtop Software Updater before version 1.5.6.16.
What is the severity of CVE-2020-12431?
CVE-2020-12431 has a severity level of medium, with a CVSS score of 6.6.
How can CVE-2020-12431 be exploited?
CVE-2020-12431 can be exploited by a local attacker to escalate their privileges to NT AUTHORITY/SYSTEM by forcing permission changes to Splashtop files and directories.
What versions of Splashtop Software Updater and Splashtop Streamer are affected by CVE-2020-12431?
Splashtop Software Updater before version 1.5.6.16 and Splashtop Streamer before version 3.3.8.0 are affected by CVE-2020-12431.
How can I fix CVE-2020-12431?
To fix CVE-2020-12431, update Splashtop Software Updater to version 1.5.6.16 or later, and update Splashtop Streamer to version 3.3.8.0 or later.