The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.
View Full Alert
Related Posts
CVE-2018-18673GNUBOARD5 5.3.1.9 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "Menu Link" parameter, aka the adm/menu_list_update.php me_link parameter. View Full Alert
CVE-2018-17792MDaemon Webmail (formerly WorldClient) has CSRF. View Full Alert
CVE-2018-14919LOYTEC LGATE-902 6.3.2 devices allow XSS. View Full Alert