CVE-2023-3181
HIGHDescription
The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using Splashtop Streamer’s Windows Installer. Since the C:\Windows\Temp~nsu.tmp folder inherits permissions from C:\Windows\Temp and Au_.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| splashtop | mirroring360_receiver |
| splashtop | mirroring360_sender |
| splashtop | splashtop |
| splashtop | splashtop |
| splashtop | splashtop_for_rmm |
| splashtop | streamer |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2023-3181? +
How severe is CVE-2023-3181? +
What products are affected by CVE-2023-3181? +
How do I check if I'm vulnerable to CVE-2023-3181? +
Related Vulnerabilities
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. …
make-initrd-ng is a tool for copying binaries and their dependencies. Local privilege escalation affecting all NixOS users. With systemd.shutdownRamfs.enable enabled …
Gradle is a build automation tool, and its native-platform tool provides Java bindings for native APIs. On Unix-like systems, the …
A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could …
Lakeside Software’s SysTrack LsiAgent Installer version 10.7.8 for Windows contains a local privilege escalation vulnerability which allows attackers SYSTEM level …