7.8
CVE-2018-19592
- EPSS 0.71%
- Veröffentlicht 27.09.2019 16:15:10
- Zuletzt bearbeitet 21.11.2024 03:58:15
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Corsair ≫ Link Version4.9.7.35
Corsair ≫ Axi Version-
Corsair ≫ Commander Mini Version-
Corsair ≫ Commander Pro Version-
Corsair ≫ H100i Version-
Corsair ≫ H100i Gtx Version-
Corsair ≫ H100i V2 Version-
Corsair ≫ H110i Version-
Corsair ≫ H110i Gt Version-
Corsair ≫ H110i Gtx Version-
Corsair ≫ H115i Version-
Corsair ≫ H80i Version-
Corsair ≫ H80i Gt Version-
Corsair ≫ H80i V2 Version-
Corsair ≫ Hxi Version-
Corsair ≫ Lighting Node Pro Version-
Corsair ≫ Rm Version-
Corsair ≫ Rmi Version-
Corsair ≫ X99 Version-
Corsair ≫ Commander Mini Version-
Corsair ≫ Commander Pro Version-
Corsair ≫ H100i Version-
Corsair ≫ H100i Gtx Version-
Corsair ≫ H100i V2 Version-
Corsair ≫ H110i Version-
Corsair ≫ H110i Gt Version-
Corsair ≫ H110i Gtx Version-
Corsair ≫ H115i Version-
Corsair ≫ H80i Version-
Corsair ≫ H80i Gt Version-
Corsair ≫ H80i V2 Version-
Corsair ≫ Hxi Version-
Corsair ≫ Lighting Node Pro Version-
Corsair ≫ Rm Version-
Corsair ≫ Rmi Version-
Corsair ≫ X99 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.71% | 0.715 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.