CVE-2023-3181
The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Temp~nsu.tmp\Au_.exe file is automatically launched as SYSTEM when the system reboots or when a standard user runs an MSI repair using Splashtop Streamer’s Windows Installer. Since the C:\Windows\Temp~nsu.tmp folder inherits permissions from C:\Windows\Temp and Au_.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.03%
- CWE
- CWE-379
- Published
- 2024-01-25
- Last modified
- 2026-03-13
Affected products
- Splashtop Splashtop Software Updater
Weakness type
Related vulnerabilities
- CVE-2025-32438 — Local privilege escalation in make-initrd-ng
- CVE-2025-27148 — Gradle vulnerable to local privilege escalation through system temporary directory
- CVE-2023-49797 — Local Privilege Escalation in pyinstaller on Windows
- CVE-2021-29428 — Local privilege escalation through system temporary directory
- CVE-2024-9950 — Abuse of Unauthenticated Compliance Recheck in SecureConnector
- CVE-2021-21100 — Adobe Digital Editions Arbitrary file system write vulnerability
- CVE-2024-9500 — Autodesk ADP Desktop SDK Privilege Escalation Vulnerability
- CVE-2023-37243 — The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM w