PT-2018-1557 · Protonvpn · Protonvpn Vpn Client

CVE-2018-4010

·

Publicado

2018-09-07

·

Atualizado

2023-02-04

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions ProtonVPN VPN client version 1.5.1
Description A code execution issue exists in the connect functionality of the ProtonVPN VPN client, allowing for privilege escalation. This can be triggered by a specially crafted configuration file, enabling an attacker to execute arbitrary commands with system privileges.
Recommendations For ProtonVPN VPN client version 1.5.1, consider disabling the connect functionality until a patch is available to prevent potential exploitation. Restrict access to configuration files to minimize the risk of a specially crafted file being used to escalate privileges.

Exploit

Correção

OS Command Injection

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-01112
CVE-2018-4010

Produtos afetados

Protonvpn Vpn Client