The C:Program Files (x86)SplashtopSplashtop Software Updateruninst.exe process creates a folder at C:WindowsTemp~nsu.tmp and copies itself to it as Au_.exe. The C:WindowsTemp~nsu.tmpAu_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using Splashtop Streamer’s Windows Installer. Since the C:WindowsTemp~nsu.tmp folder inherits permissions from C:WindowsTemp and Au_.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.
The product creates a temporary file in a directory whose permissions allow unintended actors to determine the file’s existence or otherwise access that file.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mirroring360_receiver | Splashtop | * | 2.4.0.1 (excluding) |
Mirroring360_sender | Splashtop | * | 1.3.0.0 (excluding) |
Splashtop | Splashtop | * | 3.5.6.0 (excluding) |
Splashtop | Splashtop | * | 3.5.8.0 (excluding) |
Splashtop_for_rmm | Splashtop | * | 3.5.8.0 (excluding) |
Streamer | Splashtop | * | 3.5.6.0 (excluding) |