CVE-2018-19592
The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.
Published:Sep 27, 2019
Last Modified:Nov 21, 2024
EPS:Sep 27, 2019
EPSS Score:0.00711
CVSS Score:7.8
Affected Products
Vendor
Product
Action
Vendor
Corsair
Product
Axi
Corsair
Axi
Vendor
Corsair
Product
Commander Mini
Corsair
Commander Mini
Vendor
Corsair
Product
Commander Pro
Corsair
Commander Pro
Vendor
Corsair
Product
H100i
Corsair
H100i
Vendor
Corsair
Product
H100i Gtx
Corsair
H100i Gtx
Vendor
Corsair
Product
H100i V2
Corsair
H100i V2
Vendor
Corsair
Product
H110i
Corsair
H110i
Vendor
Corsair
Product
H110i Gt
Corsair
H110i Gt
Vendor
Corsair
Product
H110i Gtx
Corsair
H110i Gtx
Vendor
Corsair
Product
H115i
Corsair
H115i
Vendor
Corsair
Product
H80i
Corsair
H80i
Vendor
Corsair
Product
H80i Gt
Corsair
H80i Gt
Vendor
Corsair
Product
H80i V2
Corsair
H80i V2
Vendor
Corsair
Product
Hxi
Corsair
Hxi
Vendor
Corsair
Product
Lighting Node Pro
Corsair
Lighting Node Pro
Vendor
Corsair
Product
Link
Corsair
Link
Vendor
Corsair
Product
Rm
Corsair
Rm
Vendor
Corsair
Product
Rmi
Corsair
Rmi
Vendor
Corsair
Product
X99
Corsair
X99
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
