CVE Vulnerabilities

CVE-2020-18171

Improper Privilege Management

Published: Jul 26, 2021 | Modified: Apr 11, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagits use of OLE is a security vulnerability unto itself and it is not. See reference document for more details

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Snagit Techsmith 19.1.0.2653 (including) 19.1.0.2653 (including)

Potential Mitigations

References