Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-10169

Опубликовано: 16 апр. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection. This plugin will execute code in the context of the SYSTEM user.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:protonmail:protonvpn:1.3.3:*:*:*:*:windows:*:*

EPSS

Процентиль: 68%
0.00583
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection. This plugin will execute code in the context of the SYSTEM user.

CVSS3: 9.8
fstec
почти 8 лет назад

Уязвимость службы ProtonVPN Service программного обеспечения для доступа к VPN-сервису ProtonVPN, позволяющая нарушителю выполнить произвольный код с привилегиями SYSTEM

EPSS

Процентиль: 68%
0.00583
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-732