Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8m5h-w7m5-3jm3

Опубликовано: 19 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.

EPSS

Процентиль: 5%
0.00023
Низкий

8.2 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.2
nvd
10 месяцев назад

In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.

CVSS3: 7.3
fstec
10 месяцев назад

Уязвимость корпоративного VPN-программного обеспечения Pritunl Client, связанная с небезопасным управлением привилегиями, позволяющая нарушителю повысить свои привилегии до уровня root

EPSS

Процентиль: 5%
0.00023
Низкий

8.2 High

CVSS3

Дефекты

CWE-863