CVE-2024-42051: High severity Splashtop Streamers vulnerability
Published Jul 28, 2024
·Updated
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by replacing InstRegExp.reg.
Affected Software
2 affected components
Splashtop Streamers<3.6.2.0
Splashtop Streamer Windows<3.6.2.0
Event History
Jul 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-42051?
CVE-2024-42051 has a high severity rating due to its potential for local privilege escalation.
2
How do I fix CVE-2024-42051?
To mitigate CVE-2024-42051, update the Splashtop Streamer to version 3.6.2.0 or later.
3
Who is affected by CVE-2024-42051?
CVE-2024-42051 affects users of Splashtop Streamer for Windows versions prior to 3.6.2.0.
4
What type of vulnerability is CVE-2024-42051?
CVE-2024-42051 is a privilege escalation vulnerability involving weak permissions during installation.
5
Can a local user exploit CVE-2024-42051?
Yes, a local user can exploit CVE-2024-42051 to replace files and escalate privileges to SYSTEM.