CVE-2024-12552: Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within WTabletServicePro.exe. By creating a symbolic link, an attacker can abuse the service to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12552?
The severity of CVE-2024-12552 is classified as high due to its ability to allow privilege escalation.
How does CVE-2024-12552 affect Wacom Center?
CVE-2024-12552 affects Wacom Center by allowing local attackers to escalate their privileges after executing low-privileged code.
Who is vulnerable to CVE-2024-12552?
Users of affected installations of Wacom Center are vulnerable to CVE-2024-12552 if an attacker has already gained low-level access.
How do I mitigate CVE-2024-12552?
To mitigate CVE-2024-12552, ensure that Wacom Center is updated to the latest version that addresses this vulnerability.
What type of attack is associated with CVE-2024-12552?
CVE-2024-12552 is associated with local privilege escalation attacks.