7.2
CVSSv2

CVE-2018-12441

Published: 11/10/2018 Updated: 24/08/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows "Everyone" group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

corsair corsair utility engine 3.7.99

corsair corsair utility engine 3.3.103

corsair corsair utility engine 3.4.95

corsair corsair utility engine 3.6.109

corsair corsair utility engine 3.2.87