PT-2018-18096 · Purevpn · Purevpn

Publicado

2018-02-26

·

Atualizado

2018-03-17

·

CVE-2018-7484

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PureVPN versions through 5.19.4.0
Description An issue was discovered where the client installation grants the Everyone group Full Control permission to the installation directory. The PureVPNService.exe service, which runs under NT AuthoritySYSTEM privileges, tries to load several dynamic-link libraries using relative paths instead of the absolute path. This makes the application susceptible to privilege escalation through DLL hijacking.
Recommendations For PureVPN versions through 5.19.4.0, consider restricting write access to the installation directory to prevent DLL hijacking. As a temporary workaround, ensure that all dynamic-link libraries are loaded using absolute paths to prevent privilege escalation.

Correção

Untrusted Search Path

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-7484

Produtos afetados

Purevpn