CVE-2020-18171
Last modified
CVE-2020-18171 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. See reference document for more details.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Techsmith | Snagit | 19.1.0.2653 |
References
- https://github.com/GitHubAssessments/CVE_Assessment_06_2019/blob/master/Snagit_Review.pdfExploit, Third Party Advisory
- https://github.com/GitHubAssessments/CVE_Assessment_06_2019/blob/master/Snagit_Review.pdfExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-18171?
How severe is CVE-2020-18171?
How do I fix CVE-2020-18171?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-18165Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote a…4.8
- CVE-2020-18166Unrestricted File Upload in LAOBANCMS v2.0 allows remote att…9.8
- CVE-2020-18167Cross Site Scripting (XSS) in LAOBANCMS v2.0 allows remote a…4.8
- CVE-2020-18169A vulnerability in the Windows installer XML (WiX) toolset o…7.8
- CVE-2020-1817Huawei PCManager with versions earlier than 10.0.1.36 has a …7.8
- CVE-2020-18170An issue in the SeChangeNotifyPrivilege component of Abloy K…9.8
- CVE-2020-18172A code injection vulnerability in the SeDebugPrivilege compo…9.8
- CVE-2020-18173A DLL injection vulnerability in 1password.dll of 1Password …7.8
- CVE-2020-18174A process injection vulnerability in setup.exe of AutoHotkey…9.8
- CVE-2020-18175SQL Injection vulnerability in Metinfo 6.1.3 via a dosafety_…9.8
- CVE-2020-18178Path Traversal in HongCMS v4.0.0 allows remote attackers to …9.8
- CVE-2020-1818There are multiple out of bounds (OOB) read vulnerabilities …5.3
Are you affected by CVE-2020-18171?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
