CVE-2020-18171

HIGH

TechSmith Snagit 19.1.0.2653 - Privilege Escalation

Title source: llm
STIX 2.1

Description

TechSmith Snagit 19.1.0.2653 uses Object Linking and Embedding (OLE) which can allow attackers to obfuscate and embed crafted files used to escalate privileges. NOTE: This implies that Snagit's use of OLE is a security vulnerability unto itself and it is not. See reference document for more details.

Scores

CVSS v3 8.8
EPSS 0.0039
EPSS Percentile 30.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
techsmith/snagit 19.1.0.2653
Published Jul 26, 2021
Tracked Since Feb 18, 2026