Exploitation Summary
EIP tracks 1 public exploit for CVE-2024-22002. PoCs published by 0xkickit.
AI-analyzed exploit summary The repository provides a functional DLL hijacking exploit for CVE-2024-22002 in CORSAIR iCUE v5.9.105, where a malicious DLL can be placed in the `cuepkg-1.2.6` directory to achieve local privilege escalation (LPE) via the `iCUEUpdateService`.
Description
CORSAIR iCUE 5.9.105 with iCUE Murals on Windows allows unprivileged users to insert DLL files in the cuepkg-1.2.6 subdirectory of the installation directory.
Exploits (1)
The repository provides a functional DLL hijacking exploit for CVE-2024-22002 in CORSAIR iCUE v5.9.105, where a malicious DLL can be placed in the `cuepkg-1.2.6` directory to achieve local privilege escalation (LPE) via the `iCUEUpdateService`.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H