6.3
CVSSv2

CVE-2020-12431

Published: 21/05/2020 Updated: 21/07/2021
CVSS v2 Base Score: 6.3 | Impact Score: 9.2 | Exploitability Score: 3.4
CVSS v3 Base Score: 6.6 | Impact Score: 5.2 | Exploitability Score: 1.3
VMScore: 561
Vector: AV:L/AC:M/Au:N/C:N/I:C/A:C

Vulnerability Summary

A Windows privilege change issue exists in Splashtop Software Updater prior to 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (prior to 3.3.8.0) and Splashtop Business (prior to 3.3.8.0).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

splashtop software updater

splashtop streamer