First published: Fri Dec 13 2024(Updated: )
This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within WTabletServicePro.exe. By creating a symbolic link, an attacker can abuse the service to create an arbitrary file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Wacom Center |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-12552 is classified as high due to its ability to allow privilege escalation.
CVE-2024-12552 affects Wacom Center by allowing local attackers to escalate their privileges after executing low-privileged code.
Users of affected installations of Wacom Center are vulnerable to CVE-2024-12552 if an attacker has already gained low-level access.
To mitigate CVE-2024-12552, ensure that Wacom Center is updated to the latest version that addresses this vulnerability.
CVE-2024-12552 is associated with local privilege escalation attacks.