CVE-2020-12431: Splashtop Software Updater
Medium severity, CVSS 6.6. EPSS: 0.6% chance of exploitation in the next 30 days.
A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking. This product is bundled with Splashtop Streamer (before 3.3.8.0) and Splashtop Business (before 3.3.8.0).
Affected products
- Splashtop Software Updater: before 1.5.6.16 (fixed in 1.5.6.16)
- Splashtop Streamer: before 3.3.8.0 (fixed in 3.3.8.0)
Published 2020-05-21. Last modified 2026-06-17.