HIGH · 7.8

CVE-2018-19592

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the cont...

Vulnerability Description

The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CorsairLink4.9.7.35
CorsairAxi-
CorsairCommander Mini-
CorsairCommander Pro-
CorsairH100I-
CorsairH100I Gtx-
CorsairH100I V2-
CorsairH110I-
CorsairH110I Gt-
CorsairH110I Gtx-
CorsairH115I-
CorsairH80I-
CorsairH80I Gt-
CorsairH80I V2-
CorsairHxi-
CorsairLighting Node Pro-
CorsairRm-
CorsairRmi-
CorsairX99-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-19592?

CVE-2018-19592 is a vulnerability with a CVSS score of 7.8 (HIGH). The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the cont...

How severe is CVE-2018-19592?

CVE-2018-19592 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-19592?

Check the references section above for vendor advisories and patch information. Affected products include: Corsair Link, Corsair Axi, Corsair Commander Mini, Corsair Commander Pro, Corsair H100I.