← Back

CVE-2018-12441

nvd nist
Published: Oct 11, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows "Everyone" group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.

Affected (5)

1 product
Corsair Utility Engine
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Corsair
Version 3.2.87
Version 3.3.103
Version 3.4.95
Version 3.6.109
Version 3.7.99

References (2)

Timeline

No history available yet.