
Cloud Vulnerability DB
A community-led vulnerabilities database
UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%\TechSmith\TechSmith Recorder\QueuedPresentations and then creating a symbolic link in %PROGRAMDATA%\Techsmith\TechSmith Recorder\InvalidPresentations that points to an arbitrary folder with an arbitrary file name. The vulnerability affects TechSmith Relay Classic Recorder prior to 5.2.1 on Windows and was introduced in SnagIT Windows 12.4.1 (NVD).
The vulnerability is classified as an Improper Link Resolution Before File Access (Link Following) issue with a CVSS v3.0 base score of 7.8 (HIGH). The vulnerability exploits the UploaderService's file movement mechanism, which checks for XML files in the QueuedPresentations folder every 30-60 seconds. When an invalid presentation is found, the service moves it to the InvalidPresentations folder while running as SYSTEM. Due to the MoveFileW() function retaining the original DACL when moving files on the same volume, the vulnerability allows for privilege escalation (SpecterOps Blog).
The vulnerability allows a low-privileged user to achieve privilege escalation to NT AUTHORITY\SYSTEM by exploiting the file movement mechanism. This enables an attacker to write files to protected locations with full control permissions, potentially leading to arbitrary code execution with SYSTEM privileges (SpecterOps Blog).
The vulnerability can be exploited by creating a symbolic link in the InvalidPresentations folder pointing to a protected location, then placing an invalid presentation file in the QueuedPresentations folder. When the service moves the file, it follows the symbolic link, resulting in a privileged file write with attacker-controlled permissions. A proof-of-concept exploit has been publicly documented (SpecterOps Blog).
The vulnerability has been fixed in SnagIt versions 2019.1.3, 2018.2.4, and 13.1.7. The fix involves using _time64 when moving files combined with a check for reparse points (FSCTL_GET_REPARSE_POINT). If a reparse point exists, it is removed (SpecterOps Blog, TechSmith Version History).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."