PT-2018-3678 · Aviatrix · Aviatrix Vpn Client

Alex Seymour

·

Publicado

2018-12-05

·

Atualizado

2020-08-24

·

CVE-2019-17388

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Aviatrix VPN Client versions through 2.2.10
Description The issue is related to weak file permissions applied to the Aviatrix VPN Client installation directory on Windows and Linux. This allows a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. The vulnerability can be exploited to allow an attacker to run arbitrary code.
Recommendations For Aviatrix VPN Client versions through 2.2.10, consider restricting access to the installation directory to prevent file modifications until a patch is available. As a temporary workaround, ensure that the file system permissions are set to prevent unauthorized modifications to the Aviatrix VPN Client installation directory. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Permission

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2021-03005
CVE-2019-17388

Produtos afetados

Aviatrix Vpn Client