VYPR
Medium severity6.6NVD Advisory· Published May 21, 2020· Updated Jun 17, 2026

CVE-2020-12431

CVE-2020-12431

Description

A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • cpe:2.3:a:splashtop:software_updater:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:splashtop:software_updater:*:*:*:*:*:*:*:*range: <1.5.6.16
    • (no CPE)range: <1.5.6.16
  • cpe:2.3:a:splashtop:streamer:*:*:*:*:-:windows:*:*+ 1 more
    • cpe:2.3:a:splashtop:streamer:*:*:*:*:-:windows:*:*range: <3.3.8.0
    • cpe:2.3:a:splashtop:streamer:*:*:*:*:business:windows:*:*range: <3.3.8.0
  • Splashtop/Software Updaterdescription
  • Range: <3.3.8.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.