VYPR
High severity7.8NVD Advisory· Published Oct 11, 2018· Updated Jun 17, 2026

CVE-2018-12441

CVE-2018-12441

Description

The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows "Everyone" group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • CORSAIR/Corsair Utility Enginellm-fuzzy6 versions
    (expand)+ 5 more
    • (no CPE)
    • cpe:2.3:a:corsair:corsair_utility_engine:3.2.87:*:*:*:*:*:*:*
    • cpe:2.3:a:corsair:corsair_utility_engine:3.3.103:*:*:*:*:*:*:*
    • cpe:2.3:a:corsair:corsair_utility_engine:3.4.95:*:*:*:*:*:*:*
    • cpe:2.3:a:corsair:corsair_utility_engine:3.6.109:*:*:*:*:*:*:*
    • cpe:2.3:a:corsair:corsair_utility_engine:3.7.99:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.