// For flags

CVE-2019-13382

 

Severity Score

7.8
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

UploaderService en SnagIT versión 2019.1.2, permite la escalada de privilegios insertando un archivo de presentación no válido en %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations y luego creando un enlace simbólico en %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations que apunta a una carpeta arbitraria con un nombre de archivo arbitrario. TechSmith Relay Classic Recorder anterior a versión 5.2.1 en Windows es vulnerable. La vulnerabilidad fue introducida en SnagIT versión 12.4.1 de Windows.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-07-07 CVE Reserved
  • 2019-07-26 CVE Published
  • 2024-07-19 EPSS Updated
  • 2024-08-04 CVE Updated
  • 2024-08-04 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-59: Improper Link Resolution Before File Access ('Link Following')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Techsmith
Search vendor "Techsmith"
Snagit
Search vendor "Techsmith" for product "Snagit"
2019.1.2
Search vendor "Techsmith" for product "Snagit" and version "2019.1.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe