7.8

CVE-2018-19592

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Corsair ≫ Link Version 4.9.7.35
   Corsair ≫ Axi Version -
   Corsair ≫ Commander Mini Version -
   Corsair ≫ Commander Pro Version -
   Corsair ≫ H100i Version -
   Corsair ≫ H100i Gtx Version -
   Corsair ≫ H100i V2 Version -
   Corsair ≫ H110i Version -
   Corsair ≫ H110i Gt Version -
   Corsair ≫ H110i Gtx Version -
   Corsair ≫ H115i Version -
   Corsair ≫ H80i Version -
   Corsair ≫ H80i Gt Version -
   Corsair ≫ H80i V2 Version -
   Corsair ≫ Hxi Version -
   Corsair ≫ Lighting Node Pro Version -
   Corsair ≫ Rm Version -
   Corsair ≫ Rmi Version -
   Corsair ≫ X99 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.09% 0.61
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

http://forum.corsair.com/v3/showthread.php?t=155646
Vendor Advisory
Release Notes
https://github.com/BradyDonovan/CVE-2018-19592/blob/master/CLink4Service
Third Party Advisory