CVE-2022-50693 Details
Description
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and escalate privileges.
A vulnerability exists in Splashtop version 8.71.12001.0 within the Splashtop Software Updater Service. This vulnerability is an unquoted service path issue that enables local attackers to execute arbitrary code. Exploitation involves injecting malicious executables into the unquoted path located in 'C:\Program Files (x86)\Splashtop\Splashtop Software Updater\'. Such actions could lead to unauthorized privilege escalation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 13, 2026CISA-ADP
Assessed Jan 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/51182 | [email protected] | Exploit |
| https://www.splashtop.com | [email protected] | Vendor |
| https://www.vulncheck.com/advisories/splashtop-unquoted-service-path | [email protected] | AdvisoryExploit |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Splashtop | <= 8.71.12001.0 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 13, 2026 | New CVE Received | [email protected] |
Volerion