PT-2018-1557 · Protonvpn · Protonvpn Vpn Client
CVE-2018-4010
·
Publicado
2018-09-07
·
Atualizado
2023-02-04
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ProtonVPN VPN client version 1.5.1
Description
A code execution issue exists in the connect functionality of the ProtonVPN VPN client, allowing for privilege escalation. This can be triggered by a specially crafted configuration file, enabling an attacker to execute arbitrary commands with system privileges.
Recommendations
For ProtonVPN VPN client version 1.5.1, consider disabling the connect functionality until a patch is available to prevent potential exploitation. Restrict access to configuration files to minimize the risk of a specially crafted file being used to escalate privileges.
Exploit
Correção
OS Command Injection
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Protonvpn Vpn Client