CVE-2019-13382
Summary
| CVE | CVE-2019-13382 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-26 13:15:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. TechSmith Relay Classic Recorder prior to 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1. |
Risk And Classification
Problem Types: CWE-59
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Snagit (Windows) Version History – TechSmith Support | CONFIRM | support.techsmith.com | Vendor Advisory |
| Security Advisory | CONFIRM | psirt.global.sonicwall.com | |
| CVE-2019–13382: Local Privilege Escalation in SnagIt | by Matt Nelson | Posts By SpecterOps Team Members | MISC | posts.specterops.io | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.