Логотип exploitDog
bind:CVE-2018-10170
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-10170

Количество 3

Количество 3

nvd логотип

CVE-2018-10170

почти 8 лет назад

NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-vxfv-xfvw-w2f5

больше 3 лет назад

NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2018-00792

почти 8 лет назад

Уязвимость службы nordvpn-service программного обеспечения для доступа к VPN-сервису NordVPN, позволяющая нарушителю выполнить произвольный код с привилегиями SYSTEM

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-10170

NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

CVSS3: 9.8
1%
Низкий
почти 8 лет назад
github логотип
GHSA-vxfv-xfvw-w2f5

NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "Connect" method accepts a class instance argument that provides attacker control of the OpenVPN command line. An attacker can specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM user.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2018-00792

Уязвимость службы nordvpn-service программного обеспечения для доступа к VPN-сервису NordVPN, позволяющая нарушителю выполнить произвольный код с привилегиями SYSTEM

CVSS3: 9.8
1%
Низкий
почти 8 лет назад

Уязвимостей на страницу