The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows Everyone group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Corsair_utility_engine | Corsair | 3.2.87 (including) | 3.2.87 (including) |
Corsair_utility_engine | Corsair | 3.3.103 (including) | 3.3.103 (including) |
Corsair_utility_engine | Corsair | 3.4.95 (including) | 3.4.95 (including) |
Corsair_utility_engine | Corsair | 3.6.109 (including) | 3.6.109 (including) |
Corsair_utility_engine | Corsair | 3.7.99 (including) | 3.7.99 (including) |