CVE-2024-9766: Wacom Center WTabletServicePro Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Wacom Center. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within WTabletServicePro process. By creating a symbolic link, an attacker can abuse the service to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-9766?
CVE-2024-9766 is considered a high-severity vulnerability that allows for local privilege escalation.
How do I fix CVE-2024-9766?
To remediate CVE-2024-9766, update Wacom Center to version 6.4.7 or later.
Who is affected by CVE-2024-9766?
CVE-2024-9766 affects installations of Wacom Center prior to version 6.4.7.
What type of attack does CVE-2024-9766 enable?
CVE-2024-9766 enables local attackers to escalate their privileges on affected systems.
What conditions must be met to exploit CVE-2024-9766?
An attacker must first execute low-privileged code on the target system to exploit CVE-2024-9766.