CVE-2024-42053: High severity splashtop vulnerability
The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a version.dll file in the folder.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42053?
The severity of CVE-2024-42053 is classified as high due to the potential for privilege escalation to SYSTEM.
How do I fix CVE-2024-42053?
To fix CVE-2024-42053, upgrade Splashtop Streamer for Windows to version 3.6.0.0 or later.
What type of vulnerability is CVE-2024-42053?
CVE-2024-42053 is a local privilege escalation vulnerability resulting from weak permissions in a temporary installation folder.
Who is affected by CVE-2024-42053?
Users of Splashtop Streamer for Windows versions prior to 3.6.0.0 are affected by CVE-2024-42053.
Can CVE-2024-42053 be exploited remotely?
No, CVE-2024-42053 requires local access to exploit, as it involves modifying files in a temporary installation folder.