Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2019-13382
TechSmith Snagit vulnerability analysis and mitigation

Overview

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. The vulnerability affects TechSmith Relay Classic Recorder prior to 5.2.1 on Windows and was introduced in SnagIT Windows 12.4.1 (NVD).

Technical details

The vulnerability is classified as an Improper Link Resolution Before File Access (Link Following) issue with a CVSS v3.0 base score of 7.8 (HIGH). The vulnerability exploits the UploaderService's file movement mechanism, which checks for XML files in the QueuedPresentations folder every 30-60 seconds. When an invalid presentation is found, the service moves it to the InvalidPresentations folder while running as SYSTEM. Due to the MoveFileW() function retaining the original DACL when moving files on the same volume, the vulnerability allows for privilege escalation (SpecterOps Blog).

Impact

The vulnerability allows a low-privileged user to achieve privilege escalation to NT AUTHORITY\SYSTEM by exploiting the file movement mechanism. This enables an attacker to write files to protected locations with full control permissions, potentially leading to arbitrary code execution with SYSTEM privileges (SpecterOps Blog).

Exploitability

The vulnerability can be exploited by creating a symbolic link in the InvalidPresentations folder pointing to a protected location, then placing an invalid presentation file in the QueuedPresentations folder. When the service moves the file, it follows the symbolic link, resulting in a privileged file write with attacker-controlled permissions. A proof-of-concept exploit has been publicly documented (SpecterOps Blog).

Mitigation and workarounds

The vulnerability has been fixed in SnagIt versions 2019.1.3, 2018.2.4, and 13.1.7. The fix involves using _time64 when moving files combined with a check for reparse points (FSCTL_GET_REPARSE_POINT). If a reparse point exists, it is removed (SpecterOps Blog, TechSmith Version History).

Additional resources


SourceThis report was generated using AI

Related TechSmith Snagit vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2010-3130HIGH9.3
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesAug 26, 2010
CVE-2020-18171HIGH8.8
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesJul 26, 2021
CVE-2020-18169HIGH7.8
  • TechSmith Snagit logoTechSmith Snagit
  • snagit
NoYesJul 26, 2021
CVE-2019-13382HIGH7.8
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesJul 26, 2019
CVE-2020-11541MEDIUM5.5
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesMay 08, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management