Vulnerability Details CVE-2024-42050
The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM via an oplock on CredProvider_Inst.reg.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.3%
CVSS Severity
CVSS v3 Score 7.0
Products affected by CVE-2024-42050
-
cpe:2.3:a:splashtop:streamer:-
-
cpe:2.3:a:splashtop:streamer:3.3.8.0
-
cpe:2.3:a:splashtop:streamer:3.5.0.0
-
cpe:2.3:a:splashtop:streamer:3.5.6.0
-
cpe:2.3:a:splashtop:streamer:3.5.8.0
-
cpe:2.3:a:splashtop:streamer:3.6.0.0
-
cpe:2.3:a:splashtop:streamer:3.6.0.1
-
cpe:2.3:a:splashtop:streamer:3.6.0.2
-
cpe:2.3:a:splashtop:streamer:3.6.0.3
-
cpe:2.3:a:splashtop:streamer:3.6.2.0
-
cpe:2.3:a:splashtop:streamer:3.6.2.1
-
cpe:2.3:a:splashtop:streamer:3.6.4.0
-
cpe:2.3:a:splashtop:streamer:3.6.4.1