Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2020-11541
TechSmith Snagit vulnerability analysis and mitigation

Overview

In TechSmith SnagIt versions 11.2.1 through 20.0.3, an XML External Entity (XXE) injection vulnerability was discovered. This security issue was assigned CVE-2020-11541 and was publicly disclosed on May 8, 2020. The vulnerability affects the Windows versions of the SnagIt software, a popular screen capture and recording tool (NVD).

Technical details

The vulnerability is classified as an XML External Entity (XXE) injection issue (CWE-611). According to the CVSS v3.1 scoring system, it received a base score of 5.5 (MEDIUM), with the vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N. Under CVSS v2.0, it was rated at 2.1 (LOW) with the vector (AV:L/AC:L/Au:N/C:P/I:N/A:N). The scoring indicates that the vulnerability requires local access and low complexity to exploit (NVD).

Impact

The vulnerability allows a local attacker to exfiltrate data under the local Administrator account. This means an attacker with local access to the system could potentially access sensitive information that should be restricted to administrator-level users (NVD).

Exploitability

The vulnerability requires local access to exploit, meaning an attacker would need physical access or local user access to the affected system. The attack complexity is considered low, indicating that the vulnerability is relatively straightforward to exploit once local access is obtained (NVD).

Mitigation and workarounds

TechSmith addressed this vulnerability by releasing version 20.1.1 of SnagIt. Users running affected versions (11.2.1 through 20.0.3) should upgrade to version 20.1.1 or later to mitigate this security risk (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related TechSmith Snagit vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2010-3130HIGH9.3
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesAug 26, 2010
CVE-2020-18171HIGH8.8
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesJul 26, 2021
CVE-2020-18169HIGH7.8
  • TechSmith Snagit logoTechSmith Snagit
  • snagit
NoYesJul 26, 2021
CVE-2019-13382HIGH7.8
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesJul 26, 2019
CVE-2020-11541MEDIUM5.5
  • TechSmith Snagit logoTechSmith Snagit
  • cpe:2.3:a:techsmith:snagit
NoYesMay 08, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management