Corsair's vulnerability footprint centers on its system-control and cooling-management software, including products such as Commander Pro and the Corsair Utility Engine alongside liquid-cooler firmware like the H100i series, where the exposure reflects application-layer access and encryption handling. The recurring weakness classes, including incorrect default permissions, insufficient information artifacts, and missing encryption of sensitive data, indicate a pattern of inadequate protection for system configuration and monitoring interfaces. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Corsair over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8808HIGH The CorsairLLAccess64.sys and CorsairLLAccess32.sys drivers in CORSAIR iCUE before 3.25.60 allow local non-privileged users (including low-integrity level processes) to read and wr | Feb 7, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-19592HIGH The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute | Sep 27, 2019 | 7.8 | 24 | NO | NO |
CVE-2018-12441HIGH The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modific | Oct 11, 2018 | 7.8 | 24 | NO | NO |
CVE-2022-35860MEDIUM Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions. | Oct 19, 2022 | 6.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Corsair.
Media articles that mention a CVE ID that affects a product developed by Corsair — matched by CVE ID, not by vendor name.