CVE-2024-42050: High severity splashtop vulnerability
Published Jul 28, 2024
·Updated
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProviderInst.reg.
Affected Software
2 affected components
Splashtop Streamer for Windows<3.7.0.0
Splashtop Streamer Windows<3.7.0.0
Event History
Jul 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42050?
CVE-2024-42050 is a high-severity vulnerability that allows local users to escalate privileges to SYSTEM.
2
How do I fix CVE-2024-42050?
To fix CVE-2024-42050, update to Splashtop Streamer for Windows version 3.7.0.0 or later.
3
What type of software is affected by CVE-2024-42050?
CVE-2024-42050 affects Splashtop Streamer for Windows versions prior to 3.7.0.0.
4
What can an attacker do with CVE-2024-42050?
An attacker can exploit CVE-2024-42050 to gain elevated privileges on the affected system.
5
Is CVE-2024-42050 a remote or local vulnerability?
CVE-2024-42050 is a local vulnerability that requires access to the affected machine.