Splashtop develops remote-access and screen-mirroring software for cross-device connectivity, with a narrowly scoped product portfolio spanning its Streamer application, mirroring utilities, and software updater components. The observed vulnerability pattern centers on resource-exposure and privilege-management weaknesses, including insecure temporary file creation and improper access controls, which reflect the intersection of local system access and inter-process communication inherent to remote-session and mirroring handlers. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Splashtop over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-50693HIGH Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. | Jan 13, 2026 | 8.4 | 30 | NO | NO |
CVE-2021-42714HIGH Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | Feb 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-42713HIGH Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions. | Feb 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-42712HIGH Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions. | Feb 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-42053HIGH The MSI installer for Splashtop Streamer for Windows before 3.6.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate pri | Jul 28, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-42052HIGH The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate pri | Jul 28, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-42051HIGH The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate pri | Jul 28, 2024 | 7.8 | 22 | NO | NO |
CVE-2023-3181HIGH The C:\Program Files (x86)\Splashtop\Splashtop Software Updater\uninst.exe process creates a folder at C:\Windows\Temp~nsu.tmp and copies itself to it as Au_.exe. The C:\Windows\Te | Jan 25, 2024 | 7.8 | 22 | NO | NO |
CVE-2024-42050HIGH The MSI installer for Splashtop Streamer for Windows before 3.7.0.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate pri | Jul 28, 2024 | 7.0 | 21 | NO | NO |
CVE-2020-12431MEDIUM A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privile | May 21, 2020 | 6.6 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Splashtop.
Media articles that mention a CVE ID that affects a product developed by Splashtop — matched by CVE ID, not by vendor name.