Vulnerabilities > Corsair > Corsair Utility Engine > 3.2.87

DATE CVE VULNERABILITY TITLE RISK
2018-10-11 CVE-2018-12441 Incorrect Default Permissions vulnerability in Corsair Utility Engine
The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system.
local
low complexity
corsair CWE-276
7.2