CVE-2024-42052: High severity splashtop vulnerability
Published Jul 28, 2024
·Updated
The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a wevtutil.exe file in the folder.
Affected Software
1 affected component
Splashtop Streamer Windows<3.5.8.0
Event History
Jul 28, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverity
Data Sourced
via NVD·03:15 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2024-42052?
CVE-2024-42052 is rated as a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2024-42052?
To fix CVE-2024-42052, update Splashtop Streamer for Windows to version 3.5.8.0 or later.
3
Who is affected by CVE-2024-42052?
CVE-2024-42052 affects Splashtop Streamer for Windows versions before 3.5.8.0.
4
What type of attack is CVE-2024-42052?
CVE-2024-42052 is an attack vector that allows local users to escalate privileges.
5
What is the exploit mechanism for CVE-2024-42052?
CVE-2024-42052 can be exploited by placing a malicious wevtutil.exe file in a temporary folder during installation.