Fix CVE-2019-13382 vulnerability in old versions of Snagit

If you are using an old version of Techsmith Snagit, you should know that the ‘local privilege escalation through insecure file movement’ vulnerability exists in your Relay Classic Recorder. To fix the vulnerability, you need to either update Snagit or disable Techsmith Uploader.

While the vulnerability CVE-2019-13382 was recognized and patched by Techsmith in the last year of 2019, we learned this through the update notification of “Snagit 13.1.5” recently, which is also affected.

Here are the vulnerability details

UploaderService in SnagIT 2019.1.2 allows elevation of privilege by placing an invalid presentation file in %PROGRAMDATA%TechSmithTechSmith RecorderQueuedPresentations and then creating a symbolic link in %PROGRAMDATA%TechsmithTechSmith RecorderInvalidPresentations that points to an arbitrary folder with an arbitrary filename. TechSmith Relay Classic Recorder prior to version 5.2.1 on Windows is vulnerable. The vulnerability was introduced in SnagIT Windows 12.4.1.

You have two options: upgrade Snagit to He follows versions or disable Techsmith Uploader Service, if you prefer the latter, follow the steps below.

  • Snagit 2019.1.3 (or later)
  • Snagit 2018.2.4
  • Snagit 13.1.7

You can download older versions of Techsmith products such as Camtasia and Snagit from on here.

Disabling Techsmith Upload Service

1. Run the following command in the Run dialog box or Windows Explorer

C:Program Files (x86)Common FilesTechSmith SharedUploader

2. Right-click the “UnInstallAndRemoveUploader.cmd” file and select Run as administrator

UninstallandRemoveUploader.cmd file

3. The service will be stopped and removed from your computer.

It’s worth noting that the current version of Snagit 2020 is full of OCR and other unwanted features.

If you don’t want to update Snagit, Uninstalling Techsmith Uploader Service is the right thing to do to protect your device.

Related articles:

How to download older version of Snagit or Camtasia?

How to uninstall and remove TechSmith Uploader Service?

How to backup and restore captures in Snagit library?

Snagit 13.0.2 allows you to override other hotkey assignments

Snagit 13: Recover the OneClick UI

Related Posts

Leave a Reply

Your email address will not be published.